Carle Foundation
Disclosed Aug 4, 201610 years ago1,185 affectedConfirmed
On June 14, 2016, the covered entity (CE), Carle Foundation Hospital, learned that its business associate (BA), The Claro Group, placed files containing protected health information (PHI) on a public computer server on February 17, 2016, potentially allowing them to become viewable via the internet. The breach affected 1,185 individuals and included demographic and clinical information as well as account numbers assigned by the CE. The CE provided breach notification to HHS, affected individuals, and the media and posted substitute notice on its website. Following the breach, the CE disabled the file transfer protocol (FTP) account where the breach occurred, reviewed all documents in the account directory for sensitive data, and migrated all users of the generic account to individual accounts. The CE also set a timeline for the implementation of various recommended controls, including two-factor authentication for all remote access to the FTP server, data loss prevention tools, configuration of appropriate logging to critical systems, and requiring high-risk vendors to complete an attestation of HIPAA Privacy and Security Rule compliance. The CE demonstrated that at the time of the
What is known
| People affected | 1,185 (as reported to HHS) |
|---|---|
| Disclosed | Aug 4, 2016 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Carle Foundation (Healthcare Provider, IL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Aug 4, 2016 | 1,185 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.