Skip to content

Martin Luther King Jr. Health Center

Disclosed Oct 25, 201312 years ago37,000 affectedConfirmed

Official notice

A transcription company’s subcontractor misconfigured its server, such that search engines, such as Google, were able to locate the server and index the records on that machine, including names, dates of service, medical record number, dates of birth and types of procedures/diagnoses). Martin Luther King Jr. Health Center, the covered entity (CE) who had retained the transcription company, Professional Transaction Services (PTC), provided breach notification to HHS, affected individuals, and the media. Once the CE learned of the breach, it initiated an investigation and learned that PTC’s subcontractor immediately disabled the server, destroyed the hard drive that stored the PHI, and worked with Google to remove the PHI from the Google caches. The CE also engaged a technical consultant to conduct forensic analyses and work to ensure that affected patients’ records could no longer be found by the most commonly used internet search engines. The CE also terminated its relationship with PTC and engaged a new transcription company. OCR obtained assurances that the CE implemented the corrective actions listed.

What is known

People affected37,000 (as reported to HHS)
DisclosedOct 25, 2013
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalOct 25, 201337,000
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Martin Luther King Jr. Health Center

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.