Oak Cliff Orthopaedic Associates
Disclosed Dec 14, 20169 years ago1,057 affectedConfirmed
On October 17, 2016, the covered entity (CE), Oak Cliff Orthopaedic Associates, received a call from the local police stating that two boxes with protected health information (PHI) pertaining to its patients were recovered from a hotel located in Texas. The boxes contained patients’ demographic, financial, and clinical information. The CE filed a police report and retrieved the boxes from the police department the next day. On Dec. 9, 2016, the CE contracted with a third-party vendor to mail breach notification to the affected individuals. The CE completed media notification and offered the affected individuals one (1) year of free identity theft protection services. In addition, it set up a call center to assists individuals with questions. The CE also improved physical security. OCR provided technical assistance regarding business associates and obtained documented assurances that the CE implemented the corrective actions noted above.
What is known
| People affected | 1,057 (as reported to HHS) |
|---|---|
| Disclosed | Dec 14, 2016 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Oak Cliff Orthopaedic Associates (Healthcare Provider, TX)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Dec 14, 2016 | 1,057 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.