Diamond Computing
Disclosed Aug 7, 201412 years ago7,016 affectedConfirmed
OCR notified the covered entity, Diatherix, that electronic protected health information (ePHI) of its patients was potentially accessible online. The CE conducted an internal investigation and determined that its business associate (BA), Diamond Computing Company, Inc., was maintaining an insecure file transfer protocol (FTP) site containing the ePHI of approximately 7,016 individuals. The ePHI involved in the breach included names, social security numbers, dates of birth, addresses, diagnoses, and billing information, as well as other data. In response to this incident, the CE engaged a data forensic firm to determine the scope and cause of the breach. The CE provided breach notification to HHS, the media, and affected individuals, and offered one year of identity theft protection. In addition, the CE performed a risk assessment, took steps to remove cached copies of ePHI from the Internet, and revised its existing policies to ensure its vendors enforce appropriate security measures to protect ePHI. As a result of OCR’s investigation, OCR obtained assurances that the corrective actions listed above were completed.
What is known
| People affected | 7,016 (as reported to HHS) |
|---|---|
| Disclosed | Aug 7, 2014 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Diamond Computing (Business Associate, GA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Aug 7, 2014 | 7,016 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.