Midwest Orthopedic Pain and Spine (MO) reported a Hacking/IT Incident to HHS OCR on 2016-07-26 affecting 29,153 individuals. The CE learned of the breach via FBI notification on May 27, 2016. The suspected vector was a third-party company with database access for patient record transfers. PHI exposed on a network server included names, addresses, dates of birth, SSNs, driver's license numbers, and clinical information. The CE replaced its IT/billing/EMR vendors, deployed new firewalls, began continuous server monitoring, and retrained staff on HIPAA.
Affected (this filing): 29,153