First Step Counseling
Disclosed Oct 23, 201213 years ago638 affectedConfirmed
From May 1, 2011, to August 5, 2011, two employees of the covered entity (CE), First Step Counseling, Inc., made photocopies of documents containing 638 patients' protected health information (PHI) and disclosed the documents to their attorney. The PHI included names, insurance numbers, diagnosis information, dates of birth, telephone numbers and social security numbers. Upon discovery of the breach, the CE hired attorneys to seek immediate return of all photocopies that contained CE's patients' PHI. The CE provided breach notification to HHS, affected individuals, and the media. As a result of OCR's investigation, the CE transferred to an electronic billing system which is password protected. In addition, the CE improved safeguards so that all patient files are locked and unlocked by the office manager, the front desk is protected by a window, and patients are not allowed to stand beside the receptionist desk. OCR obtained assurances that the CE implemented the corrective actions listed above.
What is known
| People affected | 638 (as reported to HHS) |
|---|---|
| Disclosed | Oct 23, 2012 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): First Step Counseling (Healthcare Provider, NJ)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Oct 23, 2012 | 638 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.