Back to the register

DeKalb Medical Center, Inc. d/b/a DeKalb Medical Hillandale

ArchivedSubmitted 07/15/2011
State
GA
Covered entity type
Healthcare Provider
Individuals affected
7,500
Business associate present
No
Type of breach
Theft
Location of breached information
Paper/Films
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

An employee working for the covered entity (CE) took protected health information (PHI) off premises for purposes of identity theft. Over a period of three months, the employee impermissibly accessed the PHI of 7,500 patients. The types of PHI involved in the breach included names, dates of birth, medical record and account numbers, admission or visit dates, primary diagnoses, treating physicians and in some cases social security numbers. The CE notified affected individuals, HHS, and the media about the breach. It offered a year of enhanced credit services to those affected. Upon full investigation of the breach, the CE terminated the employee. As a result of this incident, the CE initiated a corrective action plan that included revising or creating policies and procedures to prevent such incidents in the future as well as retraining of staff on its HIPAA policies and procedures. OCR’s investigation confirmed that the appropriate notifications were made and that corrective actions steps were taken.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.