Skip to content

OrthoWest

Disclosed May 14, 20188 years ago2,300 affectedConfirmed

Official notice

A former employee of CoPilot Provider Support Services, a business associate (BA), impermissibly accessed the BA's website containing the electronic protected health information (ePHI) of 1,287 patients of the covered entity (CE). The ePHI affected by this incident included patients’ names, dates of birth, addresses, and other identifiers. The CE provided breach notification to HHS, and the BA provided breach notification to the affected individuals and the media. Following the breach, the CE stopped using the BA's website to verify patients’ insurance benefits, provided HIPAA training to all of its staff members, and documented the impermissible disclosure in the affected patients’ records for accounting of disclosure purposes. In addition, the CE executed BA agreements with all of its vendors and conducted a new annual risk analysis of its ePHI. OCR obtained assurance that the CE implemented the corrective actions listed.

What is known

People affected2,300 (as reported to HHS)
DisclosedMay 14, 2018
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): OrthoWest (Healthcare Provider, OH)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalMay 14, 20182,300

Other breaches at OrthoWest

BreachAffected
Disclosed Jun 30, 2022Jun 30, 20224 years agoHacking1,369
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about OrthoWest

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.