Highlands Cashier Hospital reported to HHS on 2014-12-11 a breach involving unauthorized access or disclosure that affected 26,115 individuals. A business associate, Computer Programs and Systems, Inc., incorrectly configured the hospital's firewall, which exposed patient data on the internet. The exposed information, located on a network server, included patient names, addresses, dates of birth, treatment details, and, for 21,072 individuals, Social Security numbers. In response, the hospital implemented enhanced firewall safeguards, started monitoring web traffic, and began conducting external vulnerability scans.