Skip to content

Asante

Disclosed Sep 9, 201610 years ago2,400 affectedConfirmed

Official notice

OCR investigated the covered entity (CE), Asante, after the CE reported a breach of 2,399 individuals’ electronic protected health information (ePHI) due to a workforce member’s inappropriate access to medical records for a couple of years. It also informed OCR of similar incidents during the course of the investigation involving other workforce members. The breaches affected patients' names, ages, locations in the hospital, certain health information, and patients' status. Following the breaches and in response to OCR’s investigation, the CE sanctioned the workforce members involved and implemented a zero tolerance sanctions policy for patient information misuse. OCR obtained documentation that the CE completed security enhancements and network modifications in 2016 and 2017. Additionally, OCR obtained assurances that the CE plans to take additional measures to increase its administrative and technical safeguards of ePHI in 2017 and 2018. In this case, the employee sanctions included termination of employment.

What is known

People affected2,400 (as reported to HHS)
DisclosedSep 9, 2016
DiscoveredDec 30, 2022
HappenedJun 12, 2014
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
Oregon DOJ breach notice: Asantejustice.oregon.gov · Official notice
HHS OCR breach report (archive, resolved): Asante (Healthcare Provider, OR)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
Oregon DOJresidents of ORSep 9, 20162,282
HHS archivetotalSep 9, 20162,400
Oregon DOJresidents of ORDec 9, 2016407
Oregon DOJresidents of ORFeb 24, 20238,834
History of this record
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to insider · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 2400 · backfill source
  • 2026-09-25 · summary: empty to OCR investigated the covered entity (CE), Asante, after the CE reported a breach of 2,399 individuals’ electronic protected health information (ePHI) due to a workforce member’s inappropriate access to medical records for a couple of years. · backfill source
  • 2026-09-25 · disclosed: 2016-12-09 to 2016-09-09 · backfill source
  • 2026-09-25 · disclosed: 2023-02-24 to 2016-12-09 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Oregon DOJ), confirmed by Oregon DOJ. Record counts are as reported. Not legal advice.

Everything about Asante

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.