Skip to content

Boston Medical Center

Disclosed Apr 29, 201412 years ago15,265 affectedConfirmed

Official notice

Boston Medical Center, the covered entity (CE), engaged MDF Transcription, a business associate (BA), to provide transcription services for certain physicians. The BA subcontracted with Wave Technologies (Wave) to provide a website where transcribed notes could be reviewed by physicians of the CE. Wave contracted with Pair Networks (Pair) to provide a File Transfer Protocol (FTP) site to host the notes. On March 4, 2014, the CE discovered that the protected health information (PHI) of about 15,265 individuals was not password protected and could potentially be subject to unauthorized access. The PHI involved in the breach included names, addresses, dates of birth, and clinical information. The CE provided timely breach notification to affected individuals, the media, and HHS. As a result of OCR’s investigation, the CE contacted the BA and had the settings on the FTP site changed so that only individuals with usernames and passwords would be able to access the CE’s data. After the BA provided confirmation to the CE that the site had been reconfigured by Pair, the CE terminated its relationship with the BA. In addition, the CE created and implemented additional policies and procedure

What is known

People affected15,265 (as reported to HHS)
DisclosedApr 29, 2014
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Boston Medical Center (, MA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalApr 29, 201415,265

Other breaches at Boston Medical Center

BreachAffected
Disclosed Nov 24, 2021Nov 24, 20214 years agoInsider723
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Boston Medical Center

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.