DeKalb Medical Center
Disclosed Jul 15, 201115 years ago7,500 affectedConfirmed
An employee working for the covered entity (CE) took protected health information (PHI) off premises for purposes of identity theft. Over a period of three months, the employee impermissibly accessed the PHI of 7,500 patients. The types of PHI involved in the breach included names, dates of birth, medical record and account numbers, admission or visit dates, primary diagnoses, treating physicians and in some cases social security numbers. The CE notified affected individuals, HHS, and the media about the breach. It offered a year of enhanced credit services to those affected. Upon full investigation of the breach, the CE terminated the employee. As a result of this incident, the CE initiated a corrective action plan that included revising or creating policies and procedures to prevent such incidents in the future as well as retraining of staff on its HIPAA policies and procedures. OCR’s investigation confirmed that the appropriate notifications were made and that corrective actions steps were taken.
What is known
| People affected | 7,500 (as reported to HHS) |
|---|---|
| Disclosed | Jul 15, 2011 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): DeKalb Medical Center (Healthcare Provider, GA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jul 15, 2011 | 7,500 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.