5 Most Bizarre HIPAA Violation Cases

Choose your vendors wisely and make sure you have a Business Associate Agreement (BAA) in place.

Updated:  
December 5, 2022
HIPAA
Data Breaches
5 Most Bizarre HIPAA Violation Cases

Quick Answer: Are Covered Entities Liable When a Business Associate Mishandles PHI


Yes, covered entities share accountability for a breach even when a business associate mishandles disposal, as a 2013 case showed, where microfiche ended up in public parks.

  • On May 13, 2013, microfiche with SSNs and medical data of 277,014 patients was discarded in Dallas public parks.
  • The records had been sent to a shredding company for secure disposal.
  • Regardless of fault, the covered entity remains accountable for the breach at minimum.
  • A signed Business Associate Agreement (BAA) is essential, but choosing vendors carefully matters just as much.

Learn simple security protocols to protect patient data.

This article is an excerpt from our ebook, 5 Most Bizarre HIPAA Breaches. Download your free copy of the complete ebook.

As one of the industry’s largest data security and compliance vendors, there isn’t much we haven’t seen. But even with 11 years of breach investigation experience, every now and then we come across a data compromise that’s flat out strange.

Here’s one breach that reminds us of the importance of BAAs and a company’s need to perform due diligence before making a partnership.

See also: SecurityMetrics HIPAA Guide

The James Bond breach

In the 1977 box office hit The Spy Who Loved Me, James Bond uses a miniature microfiche reader to intercept the villain’s secret plans for a submarine tracking system. Our first breach may not be quite this exciting, but it does share Bond-era microfiche technology.

Microfiche is a storage media where documents are shrunk to about 1/25 size and copied onto photographic film. A 105x148mm microfiche card typically contains micro reproductions so small that special devices are required to read the data.

On May 13, 2013, Dallas police were notified when a local resident discovered microfiche containing sensitive patient information in a public park. Upon further investigation, police discovered three additional microfiche in two other Dallas-area public parks.

These microfiche, which contained social security numbers and medical data of 277,014 Texas Health Fort Worth Hospital patients from the ‘80s and ‘90s, had been delivered to a document shredding company for secure disposal. How these microfiche ended up in multiple public parks across Dallas remains a mystery.

Regardless of who is at fault, the covered entity at minimum shares accountability for the breach. Choose your vendors wisely and make sure you have a Business Associate Agreement (BAA) in place.

See also: You Can't Hide Behind a Business Associate Agreement