- State
- LA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 10,271
- Business associate present
- No
- Type of breach
- Theft, Unauthorized Access/Disclosure
- Location of breached information
- Electronic Medical Record
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The Louisiana State Police and the FBI notified the covered entity (CE) that a former employee was involved in identify theft affecting the protected health information (PHI) of the CE’s patients. Approximately 10,271 patients’ PHI was involved in the breach; however, the CE’s investigation concluded that after the Dept. of Public Safety and Corrections investigation, only 10 patients were affected. The PHI involved in the breach included names, addresses, and social security numbers. The CE provided breach notification to HHS, the media, and all patients whose names were included in their business associate’s (BA) information system. To prevent a similar breach from happening in the future, the BA reviewed its system and assured the CE and OCR that its system was designed to comply with the regulations under HIPAA. As a result of OCR’s investigation, the CE provided OCR with a copy of its HIPAA policies and procedures.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.