Virtua Medical Group (NJ Healthcare Provider) reported to HHS on 2016-03-11 an Unauthorized Access/Disclosure affecting 1,654 individuals. The breach was caused by Virtua's transcription vendor (business associate) who unintentionally misconfigured its server, exposing transcription documents containing patient names, birthdates, and treatment information via internet search engines. Breached information was located on Network Server and Other media. The CE terminated the vendor relationship and worked with Google to remove cached records. OCR investigated and the CE entered a consent judgment with the NJ Attorney General.
Affected (this filing): 1,654