Skip to content

Cornerstone Foot & Ankle

Disclosed Apr 16, 20188 years ago533 affectedConfirmed

Official notice

Cornerstone Foot & Ankle, the covered entity (CE), discovered that a former staff member sent spreadsheets containing protected health information (PHI) to her personal email account. The breach affected 533 individuals and the PHI involved included names, insurance information, claims information, dates of treatment, and current procedural terminology (CPT) codes. The CE provided breach notifications to HHS, all affected individuals, and the media. Following the breach, the covered entity conducted an internal investigation including a full enterprise-wide audit. Cornerstone Foot & Ankle implemented mandatory encryption on all outgoing e-mails, obtained a signed and notarized statement from the former employee stating that all emails sent to her personal email account had been deleted, and retrained staff on the provisions of the Privacy and Security Rules. OCR obtained assurances that the covered entity implemented the corrective actions noted above.

What is known

People affected533 (as reported to HHS)
DisclosedApr 16, 2018
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalApr 16, 2018533
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Cornerstone Foot & Ankle

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.