Skip to content

Arizona Dermatopathology

Disclosed Jul 25, 20197 years ago5,903 affectedConfirmed

Official notice

On May 15, 2019, a business associate (BA), American Medical Collection Agency, alerted the covered entity (CE), Arizona Dermatopathology, that the BA had discovered a potential data security incident. Upon initial review, the CE reported that the incident affected 5,903 individuals; however, after further analysis, the CE amended its report to indicate that 6,425 individuals were affected. The breach compromised the BA’s payment website and potentially the protected health information (PHI) of the CE’s patients with overdue accounts. The types of PHI involved included demographic and clinical information. In response to the breach, the CE ceased using the BA for collection efforts and informed affected individuals that payments for outstanding balances should no longer be made to AMCA. The CE provided breach notification to individuals, the media and HHS. The CE cooperated with OCR’s investigation and provided all requested documents and information to demonstrate its reasonable compliance efforts. Notably, the CE demonstrated it had a preexisting BA agreement, via Aurora Diagnostics, with the BA, that sufficiently meets the requirements of the Privacy Rule.

What is known

People affected5,903 (as reported to HHS)
DisclosedJul 25, 2019
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalJul 25, 20195,903
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Arizona Dermatopathology

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.