Silver Creek Fitness & Physical Therapy, Silver Creek Physical Therapy Gilroy, Silver Creek Physical Therapy Sunnyvale, Silver Creek Physical Therapy

Name of Entity
Silver Creek Fitness & Physical Therapy, Silver Creek Physical Therapy Gilroy, Silver Creek Physical Therapy Sunnyvale, Silver Creek Physical Therapy
Organization Type
Healthcare, Medical Providers & Medical Insurance Services
Address

CA
United States

Description
An electronic data storage account belonging to a business associate (BA), Rehab Billing Solutions, was accessible to persons outside its organization from May, 2016 to September 11, 2016. A third party security researcher from a software company accessed and downloaded protected health information (PHI) about the covered entity’s (CE) patients from this account. The types of PHI potentially involved in the breach included names, Medicare numbers, dates of birth, social security numbers, driver’s license numbers, prescriptions, treatment locations, treatment dates, and progress notes. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the BA took steps to secure the storage account and launched an investigation . The CE worked with the BA to confirm that the security researcher deleted all of the downloaded information. The CE offered one year of free credit monitoring and identity restoration services to all affected individuals. OCR reviewed the BA agreement between the CE and the BA and obtained assurances that the CE and BA implemented the corrective actions noted above.
Location of breached information: Network Server
Business associate present: No
Date of Breach
01/01/2016