Braun Internal Medicine
Disclosed Jul 14, 20179 years ago680 affectedConfirmed
On May 17, 2017, Braun Internal Medicine, P.C., the covered entity (CE), sent emails to 680 patients notifying them about a business transition. The “blind copy” feature was not used in the email and all the recipients could see the email addresses for the other recipients. The exposed protected health information (PHI) was limited to email addresses. The email contained no other PHI. In response to the breach, the CE sanctioned the responsible employee and implemented a new policy with procedures for safeguarding PHI in emails. The CE has trained all employees on the new procedures. The CE provided breach notification to HHS, affected individuals, and the media. OCR obtained assurances that the CE implemented the voluntary corrective actions noted above.
What is known
| People affected | 680 (as reported to HHS) |
|---|---|
| Disclosed | Jul 14, 2017 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Braun Internal Medicine (Healthcare Provider, GA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jul 14, 2017 | 680 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.