Cornerstone Foot & Ankle
Disclosed Apr 16, 20188 years ago533 affectedConfirmed
Cornerstone Foot & Ankle, the covered entity (CE), discovered that a former staff member sent spreadsheets containing protected health information (PHI) to her personal email account. The breach affected 533 individuals and the PHI involved included names, insurance information, claims information, dates of treatment, and current procedural terminology (CPT) codes. The CE provided breach notifications to HHS, all affected individuals, and the media. Following the breach, the covered entity conducted an internal investigation including a full enterprise-wide audit. Cornerstone Foot & Ankle implemented mandatory encryption on all outgoing e-mails, obtained a signed and notarized statement from the former employee stating that all emails sent to her personal email account had been deleted, and retrained staff on the provisions of the Privacy and Security Rules. OCR obtained assurances that the covered entity implemented the corrective actions noted above.
What is known
| People affected | 533 (as reported to HHS) |
|---|---|
| Disclosed | Apr 16, 2018 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Cornerstone Foot & Ankle (Healthcare Provider, NJ)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Apr 16, 2018 | 533 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.