Skip to content

Bon Secours Saint Francis

Disclosed Oct 26, 201510 years ago1,997 affectedConfirmed

Official notice

On July 27, 2015, the covered entity, Bon Secours St. Francis Health Systems, Inc., received a complaint that an employee was committing insurance fraud involving billing co-workers’ insurance for an experimental topical cream. The CE audited the electronic system containing protected health information (PHI) and concluded on October 15, 2015, that the employee accessed the PHI of 1,997 patients without a discernible professional need. The types of PHI involved in the breach included patients' names, dates of birth, addresses, diagnoses, treatment plans, and scanned insurance cards and driver’s licenses. The CE provided breach notification to HHS, affected individuals, and the media. In response to this incident, the CE reviewed its policies, re-trained staff, and assessed whether behavior-based auditing software programs would be an appropriate addition to current security measures. OCR obtained assurances that the CE implemented the corrective actions listed above. The CE also terminated the involved employee's employment.

What is known

People affected1,997 (as reported to HHS)
DisclosedOct 26, 2015
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalOct 26, 20151,997
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Bon Secours Saint Francis

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.