Arizona Dermatopathology
Disclosed Jul 25, 20197 years ago5,903 affectedConfirmed
On May 15, 2019, a business associate (BA), American Medical Collection Agency, alerted the covered entity (CE), Arizona Dermatopathology, that the BA had discovered a potential data security incident. Upon initial review, the CE reported that the incident affected 5,903 individuals; however, after further analysis, the CE amended its report to indicate that 6,425 individuals were affected. The breach compromised the BA’s payment website and potentially the protected health information (PHI) of the CE’s patients with overdue accounts. The types of PHI involved included demographic and clinical information. In response to the breach, the CE ceased using the BA for collection efforts and informed affected individuals that payments for outstanding balances should no longer be made to AMCA. The CE provided breach notification to individuals, the media and HHS. The CE cooperated with OCR’s investigation and provided all requested documents and information to demonstrate its reasonable compliance efforts. Notably, the CE demonstrated it had a preexisting BA agreement, via Aurora Diagnostics, with the BA, that sufficiently meets the requirements of the Privacy Rule.
What is known
| People affected | 5,903 (as reported to HHS) |
|---|---|
| Disclosed | Jul 25, 2019 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Arizona Dermatopathology (Healthcare Provider, AZ)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jul 25, 2019 | 5,903 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.