Buffalo Heart Group (NY) reported to HHS OCR on 2015-05-28 an Unauthorized Access/Disclosure breach affecting 567 individuals. A staff physician shared her password with a third party, who then remotely accessed the covered entity's EMR system. Breached ePHI included names, dates of birth, addresses, demographic and clinical information. OCR investigated and provided substantial technical assistance, requiring the CE to implement a risk analysis, risk management plan, security training, audit controls, and regular activity reviews.
Affected (this filing): 567