Skip to content

Carle Foundation

Disclosed Aug 4, 201610 years ago1,185 affectedConfirmed

Official notice

On June 14, 2016, the covered entity (CE), Carle Foundation Hospital, learned that its business associate (BA), The Claro Group, placed files containing protected health information (PHI) on a public computer server on February 17, 2016, potentially allowing them to become viewable via the internet. The breach affected 1,185 individuals and included demographic and clinical information as well as account numbers assigned by the CE. The CE provided breach notification to HHS, affected individuals, and the media and posted substitute notice on its website. Following the breach, the CE disabled the file transfer protocol (FTP) account where the breach occurred, reviewed all documents in the account directory for sensitive data, and migrated all users of the generic account to individual accounts. The CE also set a timeline for the implementation of various recommended controls, including two-factor authentication for all remote access to the FTP server, data loss prevention tools, configuration of appropriate logging to critical systems, and requiring high-risk vendors to complete an attestation of HIPAA Privacy and Security Rule compliance. The CE demonstrated that at the time of the

What is known

People affected1,185 (as reported to HHS)
DisclosedAug 4, 2016
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Carle Foundation (Healthcare Provider, IL)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalAug 4, 20161,185
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Carle Foundation

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.