Dialyze Direct, LLC (NJ healthcare provider) reported to HHS OCR that an employee fell victim to an email phishing attack, exposing PHI of 14,203 individuals. Affected data included names, dates of birth, SSNs, government IDs, financial information, medical diagnostic/treatment information, and health insurance information. The CE notified HHS, affected individuals, and the media, provided substitute notice, implemented additional administrative and technical safeguards, and offered complimentary credit monitoring.
Affected (this filing): 14,203