Aegis Medical Group (FL) reported to HHS on 2019-11-07 an Unauthorized Access/Disclosure breach affecting 9,800 individuals (8,454 per the web description). An employee misused patients' PHI for nefarious purposes. Breached information was located on Electronic Medical Records, Laptop, Network Server, and Paper/Films. PHI involved: names, dates of birth, addresses, driver's license info, SSNs, clinical info, health insurance info, diagnoses, lab results, and medications. The CE sanctioned the employee, added administrative safeguards, and retrained staff. OCR obtained corrective action assurances.
Affected (this filing): 9,800