The Texas Department of Aging and Disability Services (DADS) reported to HHS OCR on June 11, 2015 an Unauthorized Access/Disclosure breach affecting 6,600 individuals. An internal application was migrated from a private server to a public server; a software flaw allowed ePHI (names, addresses, SSNs, treatment information) to be accessed without credentials. OCR later imposed a $1.6M civil money penalty against successor entity TX HHSC for HIPAA Privacy and Security Rule violations from 2013–2017. Breached information located on Network Server.
Affected (this filing): 6,600