Skip to content

VA Corporate Data Center Operations/Austin Information Technology Center

Disclosed Jan 7, 201511 years ago7,029 affectedConfirmed

Official notice

The covered entity (CE), Veterans Health Administration, discovered that its public facing telehealth website administered by one of its business associates (BA), AuthentiDate Holding Corporation, potentially impermissibly disclosed the protected health information (PHI) of 7,054 individuals. The types of PHI potentially involved in the breach included names, addresses, birthdates, phone numbers, and VA patient identification numbers of veterans who used the telehealth system. The CE provided breach notification to individuals, HHS, and the media, and also provided credit monitoring to the affected individuals. OCR verified that the CE had a proper BA agreement in place that restricted the BA’s use and disclosure of PHI and required the BA to safeguard all PHI. Upon discovery of the breach, the CE took steps to enforce the requirements of its BA agreement and determined not to renew the agreement with the identified BA. The CE reported that they are no longer doing business with the identified BA. OCR opened a separate case to review the BA’s compliance with the HIPAA Security Rule.

What is known

People affected7,029 (as reported to HHS)
DisclosedJan 7, 2015
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalJan 7, 20157,029
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about VA Corporate Data Center Operations/Austin Information Technology Center

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.