An employee accessed and used protected health information (PHI) outside of her job duties to file fraudulent tax returns. The PHI involved in the breach included the names, addresses and social security numbers of 9,900 individuals. The covered entity (CE), Holy Cross Hospital, provided breach notification to HHS, affected individuals, and the media. The CE retrained staff, disseminated educational material, and implemented an extensive risk management plan to bolster procedures for auditing and monitoring PHI use and access. OCR obtained assurances that the CE implemented the corrective actions listed above. The CE also terminated the employment of the involved employee.
2026-09-25 · attack: unknown to lost-device · backfill source
2026-09-25 · records_basis: empty to hhs · backfill source
2026-09-25 · records: empty to 9900 · backfill source
2026-09-25 · disclosed: 2013-10-07 to 2013-09-24 · backfill source
2026-09-25 · summary: empty to An employee accessed and used protected health information (PHI) outside of her job duties to file fraudulent tax returns. The PHI involved in the breach included the names, addresses and social security numbers of 9,900 individuals. The co · backfill source