Skip to content

Virtua Medical Group

Disclosed Mar 11, 201610 years ago1,654 affectedConfirmed

Official notice

Virtua Medical Group, the covered entity (CE), reported a breach by its transcription vendor when the business associate unintentionally misconfigured its server leading to exposure of the transcription documents via an internet search engine. The CE estimated the transcription documents may have included the electronic protected health information (ePHI) of 1,654 patients’ names, birthdates and treatment information from office visits. The CE provided breach notification to HHS, the media, and the affected individuals, and posted notice to its website. As a result of OCR’s investigation, the CE contacted law enforcement, and contacted the transcription vendor to facilitate the removal of the entire site at issue from Google cache. The CE received assurances that Google removed the individual patient records that were accessible via searching the internet and that no other search engine was involved. The CE also terminated its relationship with the transcription vendor. Additionally, the CE is expected to take additional corrective actions in connection with the consent judgment entered into by CE with the Attorney General of the State of New Jersey and the New Jersey Division of C

What is known

People affected1,654 (as reported to HHS)
DisclosedMar 11, 2016
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Virtua Medical Group (Healthcare Provider, NJ)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalMar 11, 20161,654
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Virtua Medical Group

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.