Back to the register

Emory Healthcare

ArchivedSubmitted 04/18/2012
State
GA
Covered entity type
Healthcare Provider
Individuals affected
315,000
Business associate present
No
Type of breach
Other, Unknown
Location of breached information
Other
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

On February 20, 2012, the covered entity (CE), Emory Healthcare, discovered that ten unencrypted back-up compact disks (CDs) containing electronic protected health information (ePHI) were missing. The types of ePHI involved in the breach included clinical and demographic data for 315,000 surgical patients treated at three locations between September 1990 and April 2007. The information on the CDs could only easily be read using decommissioned software. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE required every department to inventory and properly store or destroy PHI. It also distributed educational material to all staff. OCR obtained assurances that the CE implemented the corrective actions listed above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.