Reading Health System
Disclosed Apr 29, 201412 years ago1,845 affectedConfirmed
A medical practice moved and a vendor/patient stored three boxes of paper medical billing records in the vendor’s crawl space from March 2012 until March 2014. The boxes contained the protected health information (PHI) of approximately 1,845 individuals. The types of PHI involved in the breach included names, addresses, dates of birth, social security numbers, insurance information, medical practice billing codes, and diagnoses. Following the breach, the covered entity (CE), Reading Health System, interviewed the vendor/patient and determined no disclosures had occurred. The CE provided breach notification to HHS and affected individuals and offered all living patients a year of free credit monitoring. The CE established a professionally staffed call
What is known
| People affected | 1,845 (as reported to HHS) |
|---|---|
| Disclosed | Apr 29, 2014 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Reading Health System (Healthcare Provider, PA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Apr 29, 2014 | 1,845 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.