Peachtree Orthopaedic Clinic, the covered entity, discovered that there had been an unauthorized intrusion into its computer system. It determined that the intruder may have been able to access the protected health information (PHI) of approximately 531,000 patients. The PHI included names, addresses, dates of birth, Social Security Numbers, and some clinical information. The covered entity retained a third party IT security firm to perform a forensic evaluation. It ended its relationship with the business associate that it concluded was the source of the compromise to its database. The covered entity also implemented several additional technical safeguards, including: a new intrusion detection system, improved its firewall, reset all of its user passwords, upgraded its anti-virus software, including additional monitoring of user activity, and implemented multi-factor authentication for remote users. As a result of OCR’s investigation, Peachtree Orthopaedic Clinic also completed a new risk analysis. It provided breach notification to HHS, the affected individuals, the media, and on its website. OCR obtained assurances that the covered entity implemented the corrective actions outli
2026-09-25 · attack: unknown to hacking · backfill source
2026-09-25 · records_basis: empty to hhs · backfill source
2026-09-25 · records: empty to 531000 · backfill source
2026-09-25 · disclosed: 2016-11-21 to 2016-11-18 · backfill source
2026-09-25 · summary: empty to Peachtree Orthopaedic Clinic, the covered entity, discovered that there had been an unauthorized intrusion into its computer system. It determined that the intruder may have been able to access the protected health information (PHI) of appr · backfill source