Ashtabula County Medical Center
Disclosed May 8, 20206 years ago3,683 affectedConfirmed
The covered entity (CE), Ashtabula County Medical Center, reported that an employee posted the protected health information (PHI) of 3,683 individuals to a public website. The PHI involved included names, diagnoses/conditions, and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. Complimentary credit monitoring services were also provided. In response to the breach, the CE sanctioned the responsible employee and revised its policies and procedures. OCR provided technical assistance to the CE regarding the HIPAA Privacy Rule.
What is known
| People affected | 3,683 (as reported to HHS) |
|---|---|
| Disclosed | May 8, 2020 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Ashtabula County Medical Center (Healthcare Provider, OH)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | May 8, 2020 | 3,683 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.