James Kagan, MD
Disclosed Dec 22, 20214 years ago1,310 affectedConfirmed
James Kagan, MD, reported that an employee was subject to a phishing attack resulting in unauthorized access to an email account containing patient information. Upon investigation, OCR determined that James Kagan, MD is not a covered entity or business associate subject to the HIPAA Privacy, Security, and Breach Notification Rules.
What is known
| People affected | 1,310 (as reported to HHS) |
|---|---|
| Disclosed | Dec 22, 2021 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): James Kagan, MD (Healthcare Provider, CO)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Dec 22, 2021 | 1,310 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.