Grace Primary Care
Disclosed Jun 7, 201610 years ago6,853 affectedConfirmed
Grace Primary Care, PC, the covered entity (CE), discovered that its business associate (BA), Bizmatics, suffered a malicious cyber-attack to its computer servers, potentially exposing the names, dates of birth, addresses, phone numbers, email addresses, social security numbers, health insurance numbers, diagnoses, and treatment information for 6,853 individuals. In addition, while the CE was completing breach notification requirements, some of the notification letters to the affected individuals were inadvertently mailed to invalid addresses due to a spreadsheet error. The CE recovered all but 135 letters, unopened, and conducted a breach risk assessment. The CE determined that the 135 letters had a low probability of impermissible disclosure, and OCR provided technical assistance to the CE concerning the elements which constitute PHI. The CE provided timely breach notification to the affected individuals, to HHS, and to the media. OCR determined that a BA agreement was in place at the time of the breach and the subsequent investigation. In response to the breach, the CE offered free identity protection services to the affected individuals, and initiated a process of terminating i
What is known
| People affected | 6,853 (as reported to HHS) |
|---|---|
| Disclosed | Jun 7, 2016 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Grace Primary Care (Healthcare Provider, TN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jun 7, 2016 | 6,853 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.