mdINR LLC (FL) reported to HHS OCR on 2015-01-05 an Unauthorized Access/Disclosure affecting 1,859 individuals. On November 3, 2014, an IT employee sent an unsecured email with an attached spreadsheet containing PHI (patient names, billing account numbers, reporting dates, internal site codes, and facility addresses) to a manufacturer representative. Breached information was located in Email. The employee received a written warning; the CE reinforced HIPAA training and role-based access controls. OCR obtained assurances of corrective action.
Affected (this filing): 1,859