James A. Fosnaugh
Disclosed Jun 26, 201313 years ago2,125 affectedConfirmed
OCR opened an investigation of the covered entity (CE), Dr. James A. Fosnaugh, after he reported that the computer chip in his thumb drive had fallen out of its casing at some point in May 2013. The thumb-drive contained the names, dates of birth, addresses, phone numbers, and in some cases, names of family members listed on family medical histories. The incident affected approximately 2,125 of the CE’s patients. The CE provided breach notification to HHS, affected individuals, and the media. To prevent similar breaches from happening in the future, the CE established a team responsible for identifying security issues as they arise. The CE also retrained employees on its policies and procedures regarding the Privacy and Security Rules. As a result of OCR’s investigation, the CE completed a risk analysis to ensure adequate safeguards of electronic protected health information.
What is known
| People affected | 2,125 (as reported to HHS) |
|---|---|
| Disclosed | Jun 26, 2013 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): James A. Fosnaugh (Healthcare Provider, NE)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jun 26, 2013 | 2,125 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.