24 ON Physicians
Disclosed Aug 15, 201412 years ago10,104 affectedConfirmed
On June 10, 2014, 24 ON Physicians, the covered entity (CE), discovered that its business associate (BA), PST Services, hired an off-shore subcontractor GeBBS, which repurposed a computer server containing the protected health information (PHI) of 10,104 of the CE’s patients. The re-use of server made the PHI potentially available over the Internet from December 1, 2013, to April 17, 2014. The PHI included patients' names, invoice numbers, procedure codes, charge amounts, balances due, policy numbers, billing-related status comments, and dates of service. In response to this breach, the CE ensured that the server was taken off-line and the PHI was destroyed. The subcontractor submitted documentation stating that all of the breached PHI was destroyed. The CE informed OCR that it no longer works with the subcontractor. The CE provided breach notification to HHS, affected individuals and the media. It also provided affected individuals with one year of free credit monitoring. The CE initiated a plan to work with its BAs to strengthen security protocols to prevent this type of breach from occurring in the future. OCR obtained assurances that the CE and BA implemented the corrective act
What is known
| People affected | 10,104 (as reported to HHS) |
|---|---|
| Disclosed | Aug 15, 2014 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): 24 ON Physicians (Business Associate, GA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Aug 15, 2014 | 10,104 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.