Pointe Medical Services
Disclosed Apr 1, 201610 years ago2,000 affectedConfirmed
The covered entity (CE), Pointe Medical Services, Inc., discovered on February 11, 2016, that a former nurse practitioner was soliciting patients to her new practice from information she had downloaded from the CE between October 23, 2015 and until she was terminated on December 15, 2015. Information on the reports included: patients' names, dates of birth, phone numbers, reasons for appointments, appointment status (i.e. no show, cancelled, etc.), service sites, diagnoses, conditions, and health insurance information including insurance providers and plan types. The breach affected 2,055 patients. The CE provided breach notification to HHS, to affected individuals, on its website and to various media outlets across Georgia and Florida. In response to the breach, the CE retrained its workforce, disabled the ability to download information to removable electronic storage devices, and increased the frequency of its electronic health record activity audits. OCR obtained assurances that the CE implemented the corrective actions listed above.
What is known
| People affected | 2,000 (as reported to HHS) |
|---|---|
| Disclosed | Apr 1, 2016 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Pointe Medical Services (Healthcare Provider, FL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Apr 1, 2016 | 2,000 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.