- State
- AL
- Covered entity type
- Healthcare Provider
- Individuals affected
- 880
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On March 22, 2011, during a house raid, the Secret Service discovered the protected health information (PHI) of approximately 880 patients of the covered entity (CE), Troy Regional Medical Center, in the form of admission “face sheets.” The PHI involved in the breach included demographic information, such as patients’ names, dates of birth, social security numbers, and medical record numbers. The CE could not accurately identify the person responsible for breaching its electronic medical record (EMR) system due to a software error which erroneously recorded multiple occasions of systems access when workforce members were accessing the system for legitimate business purposes. Due to this software error, the CE could not effectively assist in the criminal investigation being conducted by local law enforcement and the Secret Service. The CE provided breach notification to HHS, the media, and affected individuals and posted substitute notice on its website. It also provided a toll-free information number and offered credit monitoring for one year. In response to the incident, the CE worked with its IT vendor to increase data security monitoring and implement automatic log-out for its EMR system. The CE also updated and added to its policies and procedures, improved system review documentation, implemented verification of user access rights, and developed sample audit logs. The CE also retrained employees on its HIPAA security policies. OCR obtained assurances that the corrective actions listed above were completed.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.