Rehab Billing Solutions (RBS) is a business relate (BA), which handled the billing and medical records, for the covered entity (CE), genesis Physical Therapy, Inc. a third party impermissibly accessed protected health information (PHI) by exploiting a vulnerability in the BAs application that stores scanned documents. The demographic and/or financial information of 2,245 individuals was potentially involved in the hack. The ce ended the ba agreement with this BA on August 31, 2016, and did not have access to the application at the time of the hack. The ce provided hack notification to HHS, affected individuals and the media pursuant to the cut notification Rule. in response to OCRs investigation, the CE provided OCR with a copy of its BA correspondence with RBS, which contained satisfactory assurances regarding safeguarding PHI pursuant to the requirements of the privateness and Security Rules. Location of hacked information: Electronic Medical tape business colligate present: no