Virtua Medical Group
Disclosed Mar 11, 201610 years ago1,654 affectedConfirmed
Virtua Medical Group, the covered entity (CE), reported a breach by its transcription vendor when the business associate unintentionally misconfigured its server leading to exposure of the transcription documents via an internet search engine. The CE estimated the transcription documents may have included the electronic protected health information (ePHI) of 1,654 patients’ names, birthdates and treatment information from office visits. The CE provided breach notification to HHS, the media, and the affected individuals, and posted notice to its website. As a result of OCR’s investigation, the CE contacted law enforcement, and contacted the transcription vendor to facilitate the removal of the entire site at issue from Google cache. The CE received assurances that Google removed the individual patient records that were accessible via searching the internet and that no other search engine was involved. The CE also terminated its relationship with the transcription vendor. Additionally, the CE is expected to take additional corrective actions in connection with the consent judgment entered into by CE with the Attorney General of the State of New Jersey and the New Jersey Division of C
What is known
| People affected | 1,654 (as reported to HHS) |
|---|---|
| Disclosed | Mar 11, 2016 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Virtua Medical Group (Healthcare Provider, NJ)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Mar 11, 2016 | 1,654 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.