Nephropathology Associates
Disclosed Oct 16, 201510 years ago1,260 affectedConfirmed
On July 30, 2015, a physician e-mailed a spreadsheet containing 1,260 patients’ names and clinical information to a vendor that the covered entity (CE), Nephropathology Associates, PLC, was considering for a potential project. The CE notified the hospitals that had referred its patients to the CE and provided breach notification to HHS and affected individuals. The CE did not contact the media because the impermissible disclosures affected less than 500 patients in any one state. Following the breach, the CE obtained assurances from the vendor that it destroyed all files and e-mails that it received from the CE or created using the protected health information (PHI) and that the electronic PHI (ePHI) was not copied or transferred to any other entity. As a result of this incident, the CE issued a written warning to the responsible workforce member and also retrained the employee regarding safeguarding PHI. The CE reminded workforce members to safeguard PHI, including ePHI. OCR obtained assurances that the CE implemented the corrective actions listed above.
What is known
| People affected | 1,260 (as reported to HHS) |
|---|---|
| Disclosed | Oct 16, 2015 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Nephropathology Associates (Healthcare Provider, AR)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Oct 16, 2015 | 1,260 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.