Skip to content

Uncommon Care

Disclosed Jun 21, 201610 years ago13,674 affectedConfirmed

Official notice

Uncommon Care, P.A., the covered entity (CE), discovered that its business associate (BA), Bizmatics, Inc., was the victim of a computer hacking incident. The incident resulted in potential unauthorized access to the CE’s electronic medical records stored on Bizmatics’ servers. The breach affected 13,674 individuals and included patients' addresses, dates of birth, names, social security numbers, diagnoses, test results, medications, and other treatment information. The CE sent timely breach notification to HHS, to affected individuals, and to the media. The CE also posted notification about the breach on its website. In response to the breach, the CE offered one year of free credit monitoring to the affected individuals. Prior to OCR's investigation, the CE determined that its BA agreement with the BA was not fully executed and entered into an effective BA agreement on June 7, 2016. The CE decided to continue its services contract with the BA and obtained assurances from the BA that improvements have been and will be made to its computer network, servers, and network monitoring activities. OCR obtained assurances that the CE implemented the corrective actions listed above.

What is known

People affected13,674 (as reported to HHS)
DisclosedJun 21, 2016
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Uncommon Care (Healthcare Provider, NC)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalJun 21, 201613,674
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Uncommon Care

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.