Skip to content

Jones Family Practice

Disclosed May 5, 20179 years ago742 affectedConfirmed

Official notice

Jones Family Practice, the covered entity (CE), reported that an employee obtained the medical records of 742 patients on the day of her employment termination by using the CE’s electronic medical records (EMR) system. The protected health information (PHI) included patients’ names, lab results, progress notes, and patient summaries. As a result of the breach and OCR’s involvement, the CE developed a new procedure for terminating an employee’s access to its EMR system. The CE also created and executed a HIPAA compliant business associate agreement with its EMR provider, Quest Diagnostics Clinical Laboratories, Inc. The CE also provided breach notification to HHS, affected individuals, and the media. OCR obtained assurances that the CE implemented the corrective actions noted above.

What is known

People affected742 (as reported to HHS)
DisclosedMay 5, 2017
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Jones Family Practice (Healthcare Provider, NC)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalMay 5, 2017742
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Jones Family Practice

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.