Carolina Oncology Specialists
Disclosed Oct 16, 20178 years ago1,551 affectedConfirmed
On or about August 11, 2017, the covered entity (CE), Carolina Oncology Specialists, received correspondence from credit card companies addressed to three of its patients using the CE’s address. On September 6, 2017, one of the three patients reported a suspicious credit card transaction to the CE. The CE investigated and found that the perpetrator of the fraudulent transaction was a former employee who had had access to 1,551 patient files containing names, addresses, birthdates, social security numbers, and some medical information. The former employee had legitimate access to these files as an employee and it is unclear how many records she accessed in an unauthorized manner. In response to the breach, the CE notified the police and initiated an internal investigation. The police identified the same employee as the prime suspect for misusing patient information to open fraudulent credit card accounts. The CE found that there was no unauthorized access to its network or electronic medical records in the days immediately preceding the incident. To prevent such an incident in the future, the CE implemented additional technical safeguards to better track users on its network and lim
What is known
| People affected | 1,551 (as reported to HHS) |
|---|---|
| Disclosed | Oct 16, 2017 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Carolina Oncology Specialists (Healthcare Provider, NC)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Oct 16, 2017 | 1,551 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.