Skip to content

E-dreamz

Disclosed May 8, 201313 years ago9,988 affectedConfirmed

Official notice

On April 19, 2013, the credit card information of 1,924 patients of the covered entity (CE), Piedmont HealthCare, P.A., was compromised via a breach of a website hosted by one of the CE’s vendors, E-dreamz. An unauthorized person gained access to E-dreamz’s servers and obtained payment information of the CE’s patients. The protected health information (PHI) involved in the breach included patients’ names, addresses, phone numbers, email addresses, and credit card information. The CE provided breach notification to HHS, the media, and affected individuals, and offered them a year of free credit monitoring and identity theft protection. Following the breach, the CE terminated its agreement with E-dreamz and entered into a business associate (BA) agreement with a new website hosting vendor. The CE also initiated legal proceedings against E-dreamz regarding its breach of contract for storing credit card information on its server and other issues related to this incident. OCR obtained assurances that the CE implemented the corrective actions listed.

What is known

People affected9,988 (as reported to HHS)
DisclosedMay 8, 2013
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): E-dreamz (Business Associate, NC)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalMay 8, 20139,988
HHS archivetotalMay 10, 20131,924
History of this record
  • 2026-09-25 · records: 1924 to 9988 · backfill source
  • 2026-09-25 · disclosed: 2013-05-10 to 2013-05-08 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about E-dreamz

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.