A phishing attack on Critical Care, Pulmonary and Sleep Associates, PLLP's email accounts compromised the electronic protected health information (ePHI) of 23,377 individuals. The exposed data included names, addresses, dates of birth, driver's license numbers, financial details, and medical information. The entity responded by notifying affected individuals and media, sanctioning the involved workforce member, implementing new technical safeguards, updating security policies, and retraining staff. OCR provided technical assistance following the incident.
Affected (this filing): 23,377