The covered entity (CE), Pointe Medical Services, Inc., discovered on february 11, 2016, that a former nurse practitioner was soliciting patients to her new praxis from information she had downloaded from the CE between October 23, 2015 and until she was terminated on December 15, 2015. info on the reports included: patients' names, dates of birth, phone numbers, reasons for appointments, appointment status (i.e. no show, cancelled, etc.), service sites, diagnoses, conditions, and health insurance information including insurance providers and plan types. The hack affected 2,055 patients. The ce provided hack notification to HHS, to affected individuals, on its website and to various media outlets across ga and Florida. in response to the hack, the ce retrained its workforce, disabled the ability to download information to removable electronic storage devices, and increased the frequency of its electronic health record action audits. OCR obtained assurances that the CE implemented the corrective actions listed above. Location of hacked information: desktop Computer, Other Portable Electronic Device concern associate present: no