Skip to content

Nephropathology Associates

Disclosed Oct 16, 201510 years ago1,260 affectedConfirmed

Official notice

On July 30, 2015, a physician e-mailed a spreadsheet containing 1,260 patients’ names and clinical information to a vendor that the covered entity (CE), Nephropathology Associates, PLC, was considering for a potential project. The CE notified the hospitals that had referred its patients to the CE and provided breach notification to HHS and affected individuals. The CE did not contact the media because the impermissible disclosures affected less than 500 patients in any one state. Following the breach, the CE obtained assurances from the vendor that it destroyed all files and e-mails that it received from the CE or created using the protected health information (PHI) and that the electronic PHI (ePHI) was not copied or transferred to any other entity. As a result of this incident, the CE issued a written warning to the responsible workforce member and also retrained the employee regarding safeguarding PHI. The CE reminded workforce members to safeguard PHI, including ePHI. OCR obtained assurances that the CE implemented the corrective actions listed above.

What is known

People affected1,260 (as reported to HHS)
DisclosedOct 16, 2015
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalOct 16, 20151,260
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Nephropathology Associates

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.