Lister Healthcare
Disclosed Nov 9, 20169 years ago1,349 affectedConfirmed
On October 10, 2016,the covered entity (CE), Lister Healthcare Corporation, discovered that a physician employee downloaded protected health information (PHI) from the CE’s electronic health records (EHR) system on her last day of employment. The PHI downloaded by the employee included the PHI of patients that she had never treated in any capacity and that she sought to solicit. The types of PHI involved in the breach included patients' names, addresses, dates of birth, gender, social security numbers, telephone numbers, email addresses, employment status, marital status, race, ethnicity and insurance payer information, and potentially affecting 1, 349 individuals. The CE provided breach notification to HHS, affected individuals, and the media. In response to the breach, the CE contacted its EHR provider to prevent employees from downloading, printing or otherwise transferring any PHI from the EHR system without first obtaining the express approval of the CE’s Chief Executive Officer. Additionally, the CE hired outside counsel to re-train its workforce members regarding HIPAA and their obligations with respect to this breach. The CE also reviewed its HIPAA policies and procedures t
What is known
| People affected | 1,349 (as reported to HHS) |
|---|---|
| Disclosed | Nov 9, 2016 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Lister Healthcare (Healthcare Provider, AL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Nov 9, 2016 | 1,349 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.