The covered entity (CE), Children's mercy Hospital, reported that the protected health information (PHI) of 4,067 individuals stored in an online registration system by the subcontractor, Onsite Health Diagnostics, of its business associate (BA), StayWell health Management, was hacked. The hacked information included names, encrypted passwords, email addresses, physical addresses, phone numbers, genders, and dates of birth. Because the subcontractor-generated passwords were encrypted/hashed, they were rendered unusable. The CE provided hack notification to HHS, affected individuals, and the media. The CE reported that the subcontractor moved all data from the affected scheduling application, moved all of its clients to a new programming platform, and completely decommissioned the vulnerable platform. The subcontractor also conducted a comprehensive security scrutinize and found no other improper uses of protected health info or vulnerabilities. As a result of OCR's investigation, the ce provided certification substantiating all actions taken. Location of hacked information: network Server business associate present: Yes