Skip to content

Emory Healthcare

Disclosed Feb 21, 20179 years ago79,930 affectedConfirmed

Official notice

The covered entity (CE), Emory Healthcare, Inc., reported that a former employee placed files containing the electronic protected health information (ePHI) of approximately 24,000 individuals on a public server that could be accessed by unauthorized third parties. The ePHI involved included names, addresses, dates of birth, diagnoses, and treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In its mitigation efforts, the CE implemented additional administrative, technical, and security safeguards to better protect its ePHI. OCR obtained assurances that the CE implemented the corrective actions noted.

What is known

People affected79,930 (as reported to HHS)
DisclosedFeb 21, 2017
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Emory Healthcare (Healthcare Provider, GA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalFeb 21, 201779,930
HHS archivetotalDec 15, 201724,000

Other breaches at Emory Healthcare

BreachAffected
Disclosed Dec 6, 2022Dec 6, 20223 years agoInsider1,891
Ten missing backup discs held surgical records of 315,000 patientsApr 18, 201214 years agoLost or stolen device315K
History of this record
  • 2026-09-25 · records: 24000 to 79930 · backfill source
  • 2026-09-25 · disclosed: 2017-12-15 to 2017-02-21 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Emory Healthcare

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.