Cardiology Associates
Disclosed Aug 10, 201610 years ago907 affectedConfirmed
A Cardiology Associates’ employee mailed patients’ protected health information (PHI) to her personal email address without a legitimate business purpose. The breach included the PHI of 907 individuals and included names, dates of birth, and social security numbers. Following the breach, the covered entity (CE) sanctioned the employee, which included termination in this case, and notified the Federal Bureau of Investigation. OCR reviewed the CE's risk assessment to ensure compliance with the Security Rule.
What is known
| People affected | 907 (as reported to HHS) |
|---|---|
| Disclosed | Aug 10, 2016 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Cardiology Associates (Healthcare Provider, MD)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Aug 10, 2016 | 907 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.