Kraig R. Pepper, D.O
Disclosed Sep 26, 20179 years ago653 affectedConfirmed
Dr. Kraig R. Pepper, D.O., P.A. the covered entity (CE) reported that CoPilot Provider Support Services (CoPilot) suffered a data security incident exposing the protected health information (PHI) of 653 patients of the CE. The electronic PHI (ePHI) included patients’ names, addresses, dates of birth, claims information, diagnosis, and social security numbers. Following the breach, the CE provided breach notification to HHS, the media and affected individuals. As a result of OCR’s investigation, the CE executed a business associate agreement with CoPilot and revised its authorization form regarding permitted disclosures of PHI. The CE also provided one year of identity theft protection services to affected individuals. The CE is expected to perform a thorough and accurate risk analysis, establish a risk management plan, execute agreements with other business associates and document the impermissible disclosure of the affected patient’s PHI for accounting of disclosures purposes. Further, the CE is expected to perform a technical and non-technical evaluation in response to any environmental or operational changes affecting the security of ePHI that establishes the extent to which the
What is known
| People affected | 653 (as reported to HHS) |
|---|---|
| Disclosed | Sep 26, 2017 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Kraig R. Pepper, D.O (Healthcare Provider, TX)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Sep 26, 2017 | 653 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.