Options Counseling Center
Disclosed May 9, 201412 years ago2,828 affectedConfirmed
OCR opened an investigation of the covered entity (CE), Options Counseling Center, after the CE reported that, between May 1, 2011 and July 29, 2011, an employee made photocopies of documents and printed documents from the computer system containing 2,828 patients’ protected health information (PHI) and disclosed the documents to his attorney. The types of PHI involved in the breach included, variously for different individuals, patients’ names, counseling session attendance verifications, internal CE account codes, charges, payments, addresses, telephone numbers, dates of birth, health insurance account information, and account balances, as well as 46 social security numbers. Upon discovery of the breach, the CE ensured the destruction of the PHI possessed by the (then former) employee and/or his attorney, and retrained staff. The CE also implemented new safeguards, including restricting the number of personnel who hold keys to the rooms and file cabinets that contain PHI, and converting its paper billing system to an electronic billing system, which establishes password-protected role-based access rights to varying levels of information. OCR obtained assurances that the CE implem
What is known
| People affected | 2,828 (as reported to HHS) |
|---|---|
| Disclosed | May 9, 2014 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Options Counseling Center (Healthcare Provider, NJ)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | May 9, 2014 | 2,828 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.