Ad Valorem Records, Inc. Data Breach
Ad Valorem Records Breach Exposes 590 Patients' Data
What happened in the Ad Valorem Records, Inc. data breach?
The Ad Valorem Records, Inc. data breach was reported on October 11, 2024 and affected 590 individuals. The breach type was Unauthorized Access/Disclosure involving Paper/Films. This breach occurred in Tennessee. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Ad Valorem Records, Inc. Breach Details
Ad Valorem Records, Inc. Data Breach Report
Incident Overview
On October 11, 2024, Ad Valorem Records, Inc., a Tennessee-based healthcare records management company, reported a breach of protected health information (PHI) affecting 590 individuals. The breach involved unauthorized access and disclosure of patient records maintained in paper and film formats. As a business associate to covered entities, Ad Valorem Records is subject to HIPAA regulations and required to maintain strict safeguards over all patient information in its custody. The unauthorized access incident represents a significant failure in physical and administrative controls over sensitive healthcare documentation.
Discovery and Response Timeline
The specific discovery date and investigation timeline were not detailed in the breach submission, though the entity reported the incident to the Tennessee Department of Health on October 11, 2024, meeting HIPAA's 60-day notification requirement window. Ad Valorem Records initiated an investigation into the unauthorized access upon discovery, which typically involves reviewing access logs, physical security records, and employee activities. The entity was required to notify affected individuals without unreasonable delay and in no case later than 60 calendar days after discovery of the breach. As a business associate, Ad Valorem Records was also obligated to notify its covered entity clients and the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) of the breach.
Breach Mechanics and Physical Security
The breach involved unauthorized access to records stored in paper and film formats, indicating a physical security vulnerability rather than a cybersecurity incident. Paper and film-based records require strong physical controls including locked storage facilities, restricted access areas, surveillance systems, and employee access logging. Unauthorized access to such materials may have resulted from inadequate facility security, compromised locks, missing surveillance, insufficient employee screening, or insider threats. Unlike digital breaches that may be detected through system logs and network monitoring, physical document breaches can remain undetected for extended periods. The fact that this breach involved paper and film records suggests Ad Valorem Records may operate a records storage and retrieval service for healthcare providers, requiring secure warehousing of historical patient documentation.
Organizational Context and Operations
Ad Valorem Records, Inc. operates as a business associate within the healthcare ecosystem, providing records management services to covered entities such as hospitals, physician practices, and healthcare systems. The company's primary function involves storing, organizing, and retrieving patient medical records in various formats. As a business associate, Ad Valorem Records must comply with HIPAA's Business Associate Rule, which requires implementation of administrative, physical, and technical safeguards to protect all PHI. The breach of 590 patient records indicates the company maintains records for multiple healthcare providers across Tennessee. The organization's service area and client base suggest it operates at a regional scale, though the specific number of covered entity clients and total records under management were not disclosed.
Patient Impact and Affected Population
Approximately 590 individuals had their protected health information potentially compromised through unauthorized access. These patients likely received notification letters detailing the breach, the types of information exposed, and recommended protective measures. The notification process, required under HIPAA's Breach Notification Rule, must include a description of the breach, types of information involved, steps individuals should take to protect themselves, what the organization is doing to investigate and prevent recurrence, and contact information for questions. Patients affected by this breach may have experienced anxiety regarding their privacy and potential misuse of their medical information, even though the breach was discovered and reported in accordance with regulatory requirements.
Data Exposure and HIPAA Compliance Implications
Physical breaches of paper and film records represent a persistent vulnerability in healthcare despite the industry's shift toward electronic health records. HIPAA's Physical Safeguards standards require covered entities and business associates to implement facility access controls, workstation use policies, workstation security measures, and device and media controls. The breach at Ad Valorem Records suggests potential deficiencies in one or more of these areas. Business associates are contractually obligated to their covered entity clients to maintain these safeguards, and breaches may result in regulatory investigations, corrective action plans, and potential civil penalties. The OCR has historically pursued enforcement actions against business associates for inadequate physical security controls, particularly when breaches involve large volumes of records or sensitive patient populations.
Recommended Preventive Measures
Healthcare organizations and business associates storing paper records should implement comprehensive physical security programs including: restricted access with badge readers and biometric controls, 24/7 surveillance with recorded footage, regular security audits and penetration testing of physical facilities, employee background checks and ongoing security training, visitor logs and escort requirements, secure destruction protocols for records no longer needed, and regular inventory audits to detect missing or accessed records. The healthcare industry continues to experience physical breaches despite technological advances, indicating that legacy paper-based systems require sustained investment in security infrastructure. Organizations should also consider digitization projects to reduce reliance on physical storage while maintaining appropriate digital security controls.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Ad Valorem Records, Inc. Breach
Monitor credit reports from all three major bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze to prevent unauthorized credit applications
Review medical records and explanation of benefits statements from your healthcare providers for unauthorized services, treatments, or claims you did not receive; contact providers immediately if you identify suspicious activity
Monitor financial accounts and bank statements for unauthorized transactions; set up account alerts with your financial institutions for unusual activity
Consider enrolling in identity theft protection or credit monitoring services if offered by Ad Valorem Records or your healthcare provider; maintain documentation of the breach for potential future claims
Contact your healthcare providers to confirm what information was stored with Ad Valorem Records and request copies of your medical records to verify accuracy and completeness
Be cautious of unsolicited communications claiming to be from healthcare providers or insurance companies; verify any requests for personal information by calling providers directly using known phone numbers
Document all breach-related communications and expenses; consult with an attorney if you experience identity theft or fraudulent medical services as a result of this breach
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Tennessee Breaches
Search all breaches reported in Tennessee