Presbyterian Anesthesia Associates, P.A. (now known as Providence Anesthesia Associates, P.A.)
bd_972f22c692533eb2 · schema v1 · pii pii-v1
Full breach record for Presbyterian Anesthesia Associates, P.A. (now known as Providence Anesthesia Associates, P.A.) →Credit card and contact information of 9,988 patients of Presbyterian Anesthesia Associates, P.A. (now Providence Anesthesia Associates, P.A.) was compromised when an unauthorized actor accessed servers of its website-hosting business associate, E-dreamz, Inc. Compromised PHI included names, addresses, phone numbers, email addresses, and credit card information. The CE notified HHS, the media, affected individuals, the FBI, the NC Attorney General, and major card brands; offered one year of credit monitoring and identity theft protection; engaged a forensic specialist; terminated the BA relationship; and updated HIPAA policies. OCR obtained assurances that corrective actions were implemented.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 8, 2013
- Raw hash
- 2d8cd6eddf46648a3e3f251d9d4f288483dd2ef844db56ab8a56dd50c9f28f35
Source filing
Reporting entity
- Name
- E-dreamz, Inc.norm: e dreamz
- Industry
- Website Hosting / IT Services
Victim entity
- Name
- Presbyterian Anesthesia Associates, P.A. (now known as Providence Anesthesia Associates, P.A.)norm: presbyterian anesthesia associates pa now known as providence anesthesia associates
- Industry
- Healthcare - Anesthesiology
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 9,988
- Data types
- PHIPIIPCIIDENTITY_BASICFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- Threat actor
- ExternalFinancial
- Regulator citations
- HHS OCR breach reportNorth Carolina Attorney General notificationFBI notificationMajor credit card companies notified
- Third party
- via E-dreamz, Inc.business associate
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.