Skip to content

Lebanon Cardiology Associates

Disclosed Nov 14, 20169 years ago537 affectedConfirmed

Official notice

A business associate (BA), Ambucor Health Solutions, for the covered entity (CE), Lebanon Cardiology Associates, reported a breach by a rogue employee. The CE and BA both reported the breach to HHS. The BA's employee, who is now incarcerated on unrelated matters, downloaded protected health information (PHI) onto two portable computer drives (i.e., "thumb" drives) which have been recovered. The types of PHI that were involved varied by patient, but may have included the first and last names, phone numbers, diagnoses, medications, dates of birth, race, home addresses, testing data, patient identification numbers, and medical device information of 537 of the CE’s patients. In addition, the thumb drives contained the social security numbers of about 650 patients of several covered entities with PHI that was also affected by the same breach incident. OCR reviewed a copy of the signed BA agreement between the BA and the CE. OCR confirmed that breach notification letters were mailed to affected individuals on June 27, 2016. This investigation has been consolidated into an existing review filed by the BA to ensure that all the requirements under the Breach Notification Rule have been met.

What is known

People affected537 (as reported to HHS)
DisclosedNov 14, 2016
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalNov 14, 2016537
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Lebanon Cardiology Associates

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.