HealthSource of Ohio
Disclosed Feb 26, 201412 years ago8,845 affectedConfirmed
Health Source of Ohio, the covered entity (CE), reported that its business associate (BA) uploaded a file onto its network webhosting server, which was searchable via the Internet. This breach affected the electronic protected health information (ePHI) of 8,845 individuals. The ePHI involved included Social Security numbers, addresses, drivers’ license numbers, dates of birth, financial information, and other identifiers. The CE notified HHS, affected individuals, the media, and created a complimentary phone number for questions or concerns. The CE also provided complimentary credit monitoring and identity protection services to affected individuals. In response to the breach, the CE terminated its business associate agreement with its BA and implemented additional administrative and technical safeguards. OCR obtained assurances that the CE implemented the corrective actions noted.
What is known
| People affected | 8,845 (as reported to HHS) |
|---|---|
| Disclosed | Feb 26, 2014 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): HealthSource of Ohio (, OH)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Feb 26, 2014 | 8,845 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.