Orleans Medical Clinic
Disclosed Aug 19, 201610 years ago6,890 affectedConfirmed
Hackers gained access to the covered entity’s (CE) unsecured computer server from April 5, 2016, through April 17, 2016, after its business associate (BA), ProBleu, upgraded its servers and left a port open to the internet. The server contained the protected health information (PHI) of approximately 6,890 individuals, including demographic and clinical information. The CE, Orleans Medical Clinic (OMC), provided breach notification to HHS, affected individuals, and the media on August 19, 2016, and also reported the breach to the Indiana Attorney General’s office and the FBI. To prevent similar breaches from happening in the future, OMC retained Pondurance, a forensic information technology firm. Pondurance concluded that the BA failed to take the necessary steps to secure the CE’s server by implementing the required technical safeguards. The CE terminated its relationship with the BA in July of 2016, created a policy and procedure regarding the Breach Notification requirements, and trained its workforce on its security awareness policies and procedures. OCR provided technical assistance and obtained documented assurances that the CE implemented the corrective actions listed above.
What is known
| People affected | 6,890 (as reported by the organization) |
|---|---|
| Disclosed | Aug 19, 2016 |
| Happened | Apr 5, 2016 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2016 data breach report: Orleans Medical Clinicin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Orleans Medical Clinic (Healthcare Provider, IN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Aug 19, 2016 | 6,784 |
| HHS archivetotal | Aug 19, 2016 | 6,890 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · summary: empty to Hackers gained access to the covered entity’s (CE) unsecured computer server from April 5, 2016, through April 17, 2016, after its business associate (BA), ProBleu, upgraded its servers and left a port open to the internet. The server conta · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.