VA Corporate Data Center Operations/Austin Information Technology Center
Disclosed Jan 7, 201511 years ago7,029 affectedConfirmed
The covered entity (CE), Veterans Health Administration, discovered that its public facing telehealth website administered by one of its business associates (BA), AuthentiDate Holding Corporation, potentially impermissibly disclosed the protected health information (PHI) of 7,054 individuals. The types of PHI potentially involved in the breach included names, addresses, birthdates, phone numbers, and VA patient identification numbers of veterans who used the telehealth system. The CE provided breach notification to individuals, HHS, and the media, and also provided credit monitoring to the affected individuals. OCR verified that the CE had a proper BA agreement in place that restricted the BA’s use and disclosure of PHI and required the BA to safeguard all PHI. Upon discovery of the breach, the CE took steps to enforce the requirements of its BA agreement and determined not to renew the agreement with the identified BA. The CE reported that they are no longer doing business with the identified BA. OCR opened a separate case to review the BA’s compliance with the HIPAA Security Rule.
What is known
| People affected | 7,029 (as reported to HHS) |
|---|---|
| Disclosed | Jan 7, 2015 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): VA Corporate Data Center Operations/Austin Information Technology Center (Healthcare Provider, TX)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jan 7, 2015 | 7,029 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.
Everything about VA Corporate Data Center Operations/Austin Information Technology Center