Cardiology Associates (MD) reported to HHS OCR on 2016-08-10 an Unauthorized Access/Disclosure affecting 907 individuals. A Cardiology Associates employee emailed patients' PHI to her personal email address without a legitimate business purpose. Breached information was located in Email. Exposed data included names, dates of birth, and Social Security numbers. The employee was terminated and the FBI was notified. OCR reviewed the CE's risk assessment for Security Rule compliance.
Affected (this filing): 907