First coast podiatric surgery and wound
Disclosed Aug 27, 20188 years ago500 affectedConfirmed
On August 16, 2018, First Coast Podiatric Surgery and Wound, the covered entity (“CE”), discovered that its billing software, managed by its business associate (“BA”), NextGen, had experienced an IT incident causing the log-in page for one clinic to show as the log-in page for other clinics. The CE initially reported that approximately 500 individuals were affected, but after further investigation, the CE concluded that no protected health information (PHI) was involved in the IT incident. Though an IT incident occurred, the log-in page still required authorized username and password information in order to access any PHI; and PHI was not at any time accessed by unauthorized individuals. Because the CE determined there was no reportable breach of PHI, and no affected individuals, it did not provide individual notification. OCR obtained assurances that no reportable breach occurred.
What is known
| People affected | 500 (as reported to HHS) |
|---|---|
| Disclosed | Aug 27, 2018 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): First coast podiatric surgery and wound (Business Associate, FL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Aug 27, 2018 | 500 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.