Braun Dermatology & Skin Cancer Center
Disclosed Jul 28, 20179 years ago1,200 affectedConfirmed
The covered entity (CE) sent an email to patients that failed to conceal the email addresses of the other recipients. The breach included the protected health information (PHI) of 1,200 individuals, specifically email addresses. Following the breach, the CE's Privacy Officer worked with its Information Technology (IT) Department to attempt to recall the message. The CE performed a breach risk assessment and determined there was a low risk of compromise to patients’ PHI. The CE implemented a new policy and procedure whereby it eliminated mass emails and will send individual emails through a secure patient reminder system. OCR obtained assurances that the CE implemented the corrective actions noted.
What is known
| People affected | 1,200 (as reported to HHS) |
|---|---|
| Disclosed | Jul 28, 2017 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Braun Dermatology & Skin Cancer Center (Healthcare Provider, DC)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jul 28, 2017 | 1,200 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.