- State
- NC
- Covered entity type
- Healthcare Provider
- Individuals affected
- 2,300
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Desktop Computer
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Computer malware was detected on the covered entity’s (CE) unencrypted billing software program, “Therapist Helper.” The CE did not know when the malware entered its system. Approximately 2,300 individuals were potentially affected by this malware virus. The types of protected health information (PHI) involved included demographic, financial (claims information), and clinical information (diagnoses/conditions, medications, lab results, and other treatment information). Following the breach, the CE applied security and privacy safeguards, mitigated harm, and implemented sanctions. The CE also reported working and cooperating with the local law enforcement. As a result of OCR’s investigation, the CE implementing processes and deployed software to detect, prevent, and mitigate malware on its computers, installed new computers and systems to segregate electronic PHI, and implemented additional procedures to increase awareness of and ensure compliance with technical and physical safeguards. The CE also placed an accounting of disclosures in the medical records of the affected individuals, and complied with the applicable notification provisions of the Breach Notification Rule.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.