On June 14, 2016, Carle Foundation Hospital (The Carle Foundation) discovered that its business associate, The Claro Group, placed PHI-containing files on a public FTP server on February 17, 2016, potentially making them viewable via the internet. The breach affected 1,185 individuals and involved demographic, clinical, and account number information. The CE notified HHS, affected individuals, and media. Remediation included disabling the FTP account, individual account migration, and controls including 2FA and DLP tools. OCR obtained documented assurances of corrective actions.
Affected (this filing): 1,185