Credit card and contact information of 9,988 patients of Presbyterian Anesthesia Associates, P.A. (now Providence Anesthesia Associates, P.A.) was compromised when an unauthorized actor accessed servers of its website-hosting business associate, E-dreamz, Inc. Compromised PHI included names, addresses, phone numbers, email addresses, and credit card information. The CE notified HHS, the media, affected individuals, the FBI, the NC Attorney General, and major card brands; offered one year of credit monitoring and identity theft protection; engaged a forensic specialist; terminated the BA relationship; and updated HIPAA policies. OCR obtained assurances that corrective actions were implemented.
Affected (this filing): 9,988