ABCDEFGHIJKLMNOPQRSTUVWXYZAAABACADAEAFAG
1
Name of Covered EntityStateCovered Entity TypeIndividuals AffectedBreach Submission DateType of BreachLocation of Breached InformationBusiness Associate PresentWeb DescriptionransomwareIncludes Financial information?Includes Diagnoses?Includes Addresses?Includes Drivers’ license information?Includes Names?Includes Email?Includes Phone numbers?Includes Photos?Includes Birthdates?Includes Gender?Includes Health insurance information?Includes X-ray images?Includes Ethnicity?Includes Treatment information?Includes Medical records?Includes Identification numbers?Includes Medication information?Includes Employment information?Includes Dental records?Includes Vaccination status?Includes Social security?Includes Demographic information?Includes Passport information?
2
Orlando VA Medical Center
FL
Healthcare Provider
9,8502024-03-05
Unauthorized Access/Disclosure
EmailNoThe Orlando VA Medical Center, the covered entity (CE), reported that an employee emailed documents containing the protected health information (PHI) of 9,850 individuals to a personal email account. The PHI involved included names, addresses, telephone numbers, email addresses, Social Security numbers, and birthdates. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the CE provided complimentary credit monitoring services to affected individuals and obtained a court order requiring the safeguarding of PHI.Nonames, addresses, telephone numbers, email addresses, Social Security numbersnamesemail addressestelephone numbersbirthdatesSocial Security numbersSocial Security numbers
3
Bay Area Anesthesia, LLC
FL
Healthcare Provider
15,1962024-02-26
Hacking/IT Incident
Network ServerYesThe covered entity (CE), Bay Area Anesthesia, reported that its business associate (BA) experienced a cyber-attack that affected the protected health information (PHI) of 15,196 individuals. The PHI involved included names, addresses, dates of birth, and Social Security numbers. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards. Workforce members were retrained to better protect PHI.Nonames, addresses, dates of birth, and Social Security numbersnamesdates of birthSocial Security numbersSocial Security numbers
4
Human Affairs International of California
CA
Business Associate
18,3472024-02-16
Unauthorized Access/Disclosure
Paper/FilmsYesThe covered entity (CE), Human Affairs International of California, reported that it experienced a programming issue which resulted in an employee mailing the protected health information (PHI) of 18,347 individuals to the wrong recipients. The PHI involved included names, dates of birth, addresses, diagnoses, claims and financial information, and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards. Staff were retrained on the requirements to protect and secure sensitive data.Nofinancial information, claimsdiagnosesaddressesnamesdates of birthother treatment information, treatment information
5
Forward Healthcare, LLC
MD
Healthcare Provider
3,9992024-02-08
Hacking/IT Incident
Network ServerYesThe covered entity (CE), Forward Healthcare, reported that its business associate (BA) experienced a cybersecurity incident that affected the protected health information (PHI) of 3,999 individuals. The PHI involved included names, addresses, dates of birth, and treatment information. The CE notified HHS and the affected individuals. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards to better protect its PHI.Nonames, addresses, dates of birthnamesdates of birthtreatment information
6
Humana Inc.KYHealth Plan6,4402024-02-06
Unauthorized Access/Disclosure
Paper/FilmsNoThe covered entity (CE), Humana, reported that an employee inadvertently mailed the protected health information (PHI) of 6,440 individuals to the wrong recipients. The PHI involved included names, addresses, medications, and diagnoses. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE implemented additional administrative, technical, and security safeguards to better protect its PHI.Nonames, addresses, medications, and diagnosesnames, addresses, medications, and diagnosesnames, addresses, medications, and diagnoses
7
Kentucky Cabinet for Health and Family Services
KYHealth Plan8572024-02-05
Unauthorized Access/Disclosure
Paper/FilmsYesKentucky Cabinet for Health and Family Services, reported that an employee of its business associate (BA) inadvertently mailed the protected health information (PHI) of 857 individuals to the wrong recipients. The PHI involved included names, identification numbers, claims and financial information, and other treatment information. The BA notified HHS, affected individuals and the media. In its mitigation efforts, the BA implemented additional administrative safeguards and quality assurance procedures to prevent this issue from reoccurring.Noclaims and financial informationnamesother treatment informationidentification numbers
8
Coppola Physical Therapy and Fitness Gyms
NH
Healthcare Provider
6322024-01-31
Unauthorized Access/Disclosure
EmailYesNo
9
Humana Inc.KYHealth Plan12,5392024-01-22
Unauthorized Access/Disclosure
Paper/FilmsNoThe covered entity (CE), Humana, reported that an employee inadvertently mailed the protected health information (PHI) of 12,539 individuals to the wrong recipients. The PHI involved included names, addresses, medications, and diagnoses. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE implemented additional administrative, technical, and security safeguards to better protect its PHI.Nomedications and diagnosesaddressesnamesmedications
10
Mount Vernon Dental Smiles
VA
Healthcare Provider
1,0742024-01-19
Unauthorized Access/Disclosure
EmailNoMount Vernon Dental Smiles, the covered entity (CE), reported that a workforce member inadvertently sent an email containing the protected health information (PHI) of 1,074 patients to an unauthorized individual. The PHI involved included names, dates of birth, addresses, email addresses, health insurance information, and other treatment information. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the CE strengthened its administrative safeguards to better protect sensitive data. OCR provided technical assistance regarding the HIPAA Rules.Noaddresses, email addressesnamesemail addressesdates of birthhealth insurance informationother treatment information
11
North Kansas City Hospital
MO
Healthcare Provider
502,4382024-01-03
Hacking/IT Incident
Network ServerYesThe covered entity (CE), North Kansas City Hospital, reported that its business associate (BA) experienced a cyber-attack that affected the protected health information (PHI) of 502,438 individuals. The PHI involved included names, dates of birth, addresses, claims information, diagnoses, and other treatment information. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE terminated its business relationship with the BA and implemented additional administrative safeguards to better protect PHI. Nodiagnoses, other treatment informationaddressesnamestreatment information
12
Transformative Healthcare, on behalf of Fallon Ambulance Services
MA
Healthcare Provider
911,7572023-12-31
Hacking/IT Incident
Electronic Medical Record, Network Server
NoFallon Ambulance Services (Fallon), a former subsidiary of Transformative Healthcare, the covered entity (CE), reported that it experienced a ransomware attack that compromised the protected health information (PHI) of 911,757 individuals. The PHI involved included names, addresses, birthdates, drivers’ license and Social Security numbers, diagnoses, lab results, medications, and claims and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In its mitigation efforts, the CE provided complimentary identity protection services to affected individuals. Fallon ceased medical transportation operations; therefore, OCR closed the case.Yesdiagnoses, lab results, medicationsaddressesdrivers’ license numbersnamesbirthdatesclaims and other treatment informationSocial Security numbersmedications
13
RevSpring, Inc.TN
Business Associate
1,0532023-12-22
Unauthorized Access/Disclosure
Network ServerYesThe business associate (BA), RevSpring, reported that a software coding error allowed the protected health information (PHI) of 1,053 individuals to be viewable by others. The PHI involved included names, addresses, diagnoses and other treatment information. The BA notified HHS, affected individuals, and the media. In response to the breach, the BA implemented additional administrative, technical, and security safeguards. Workforce members were also retrained on the requirements to protect and secure sensitive data.Nodiagnoses and other treatment informationaddressesnames
14
Lone Peak Physical Therapy, Inc.
MT
Healthcare Provider
5,8092023-12-21TheftPaper/FilmsNoNo
15
Rush System for Health
IL
Healthcare Provider
4,9612023-12-21
Unauthorized Access/Disclosure
EmailNoThe covered entity (CE), Rush System for Health, reported that an employee mailed the protected health information (PHI) of 4,961 individuals in a manner in which PHI was inadvertently disclosed. The PHI involved included names only. The CE notified HHS, affected individuals, and the media. In response to the incident, the CE sanctioned the responsible individual and strengthened its administrative safeguards to better protect PHI. Staff were retrained. Nonames only
16
BlueCross BlueShield of Tennessee, Inc.
TNHealth Plan1,6762023-12-19
Hacking/IT Incident
Network ServerYesThe covered entity (CE), BlueCross BlueShield of Tennessee, reported that a vendor of its business associate (BA) experienced a cyber-attack that compromised the protected health information (PHI) of 1,676 individuals. The PHI involved included names, birthdates, claims and financial information, and health insurance and other treatment information. The CE notified HHS, affected individuals, and the media.Noclaims and financial informationnamesbirthdateshealth insurance and other treatment informationhealth insurance and other treatment information
17
BELLIN HEALTHWI
Healthcare Provider
20,7902023-12-19
Hacking/IT Incident
Network ServerNoThe covered entity (CE), Bellin Health, reported that it experienced a cyberattack that compromised the protected health information (PHI) of 20,790 individuals. The PHI involved included names, addresses, dates of birth, phone numbers, Social Security numbers, health insurance information, diagnoses, and other treatment information. The CE notified HHS, the affected individuals, and the media. In its mitigation efforts, the CE provided complimentary credit monitoring services and strengthened its administrative and technical safeguards to better protect sensitive data.Nodiagnoses, other treatment informationaddressesnamesphone numbersdates of birthhealth insurance informationother treatment informationSocial Security numbersSocial Security numbers
18
AccessOne Medcard, Inc.
SC
Business Associate
8,0492023-12-15
Hacking/IT Incident
Network ServerYesThe business associate (BA), AccessOne Medcard, reported that it experienced a cyber-attack that affected the protected health information (PHI) of 8,049 individuals. The PHI involved included names, dates of birth, addresses, and financial information. The BA notified HHS, affected individuals, and the media. In response to the breach, the BA implemented additional administrative, technical, and security safeguards to better protect its PHI.Nofinancial informationaddressesnames
19
Independent Vision Group, LTD
WI
Healthcare Provider
2,9312023-12-13
Hacking/IT Incident
EmailNoThe covered entity (CE), Independent Vision Group, reported that an employee was the victim of an email phishing scheme that compromised the protected health information (PHI) of approximately 2,931 individuals. The PHI involved included names, addresses, dates of birth, drivers’ license and Social Security numbers, claims and financial information, diagnoses, and health insurance information. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the CE offered complimentary credit monitoring services and implemented additional administrative and technical safeguards to protect PHI. Staff were retrained on email security precautions. OCR provided technical assistance regarding the HIPAA Rules.Noclaims and financial informationdiagnosesaddressesdrivers’ license and Social Security numbersnamesdates of birthhealth insurance information
20
Yorkshire Wellness Group, Corp.
NM
Healthcare Provider
1,0002023-12-12
Unauthorized Access/Disclosure
Paper/FilmsNo2Yorkshire Wellness Group report that a storage facility containing the medical records of 1,000 individuals were sold at auction. OCR determined that Yorkshire does not meet the definition of a covered entity or a business associate and therefore, has no jurisdiction to investigate further.No
21
EMS Management and Consultants Inc.
NC
Business Associate
2,6542023-12-01
Unauthorized Access/Disclosure
Paper/FilmsYesEMS Management and Consultants, a business associate (BA), reported that an employee mailed the protected health information (PHI) of 2,564 individuals to the wrong recipients. The PHI involved included names, addresses, treatment information, and financial information. The BA notified HHS, affected individuals, the media, and provided substitute notice. In its mitigation efforts, the CE implemented additional administrative safeguards to better protect PHI.Nofinancial informationaddressesnamestreatment information
22
Neuromusculoskeletal Center of the Cascades, PC
OR
Healthcare Provider
19,3732023-12-01
Hacking/IT Incident
EmailNoThe covered entity (CE), Neuromusculoskeletal Center of the Cascades, reported that several employees were the subjects of an email phishing scheme that affected the protected health information (PHI) of 19,373 individuals. The PHI involved included names, Social Security numbers, addresses, drivers’ license numbers, dates of birth, diagnoses, medications, treatment information, and financial and claims information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards to better protect its PHI.Nofinancial and claims informationdiagnosesaddressesdrivers’ license numbersnamestreatment information
23
West Anaheim Medical Center
CA
Healthcare Provider
1,1662023-11-29
Hacking/IT Incident
Network ServerYesWest Anaheim Medical Center, the covered entity (CE), reported that its business associate (BA) experienced a cyber-attack that compromised the protected health information (PHI) of 1,166 individuals. The PHI involved included names, Social Security numbers, addresses, birthdates, and other treatment information. In its mitigation efforts, the CE provided complimentary credit monitoring services and the CE and BA implemented additional administrative, technical, and security safeguards.Noaddresses, Social Security numbersnamesbirthdatesother treatment information
24
Fenway Community Health Center, Inc.
MA
Healthcare Provider
5992023-11-29
Unauthorized Access/Disclosure
Paper/FilmsYesThe covered entity (CE), Fenway Community Health Center, reported that an employee of its business associate (BA) inadvertently sent the protected health information (PHI) of 599 individuals to the wrong recipients. The PHI involved included names, addresses, and treatment information. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE implemented additional administrative and technical safeguards to better protect PHI. Staff were retrained. OCR provided technical assistance regarding the HIPAA Rules.Nonames, addresses, and treatment informationnames, addresses, and treatment informationnames, addresses, and treatment information
25
Lakeview Healthcare System, LLC
FL
Healthcare Provider
2,4952023-11-27Theft
Other Portable Electronic Device, Paper/Films
NoThe covered entity (CE), Lakeview Healthcare System, reported that it someone broke into its office and stole three mobile device and paper medical records. This breach affected the protected health information (PHI) of approximately 2,495 individuals. The PHI involved included names, addresses, dates of birth, drivers’ license and Social Security numbers, financial and claims information, diagnoses, lab results, and medications. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE provided complimentary credit monitoring and theft protection services, implemented new policies and procedures, and strengthened its physical safeguards to protect and safeguard PHI.Nofinancial and claims informationdiagnosesaddressesdrivers’ license and Social Security numbersnamesdates of birthlab results, and medicationsmedications
26
California Physicians’ Service d/b/a Blue Shield of California
CAHealth Plan636,8492023-11-17
Hacking/IT Incident
Network ServerYesCalifornia Physicians’ Service dba Blue Shield of California, the covered entity (CE), reported that its business associate (BA) experienced a cyber-attack that compromised the protected health information (PHI) of 636,849 individuals. The PHI involved included names, Social Security numbers, diagnoses, addresses, birthdates, and claims information. In its mitigation efforts, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards.Nodiagnosesaddressesnamesbirthdates
27
Blue Shield of California OR Blue Shield of California Promise Health Plan
CA
Business Associate
27,8322023-11-17
Hacking/IT Incident
Network ServerYesBlue Shield of California OR Blue Shield of California Promise Health Plan, the covered entity (CE), reported that its business associate (BA) experienced a cyber-attack that compromised the protected health information (PHI) of 27,832 individuals. The PHI involved included names, Social Security numbers, diagnoses, addresses, birthdates, and claims information. In its mitigation efforts, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards.Nodiagnosesaddressesnamesbirthdates
28
Medical College of Wisconsin
WI
Healthcare Provider
240,6672023-11-14
Hacking/IT Incident
Network ServerNoThe covered entity (CE), Medical College of Wisconsin, reported that its third-party vendor experienced a cybersecurity incident that allowed unauthorized access to its server and compromised the protected health information (PHI) of 240,667 individuals. The PHI involved included names, addresses, Social Security numbers, dates of birth, claims information, diagnoses, lab results, and medications. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the CE provided credit monitoring services and terminated its business relationship with the vendor.Nodiagnoses, lab resultsaddressesnamesdates of birthSocial Security numbersmedications
29
Medical University of South Carolina
SC
Healthcare Provider
1,7582023-11-13
Unauthorized Access/Disclosure
Network ServerNoThe covered entity (CE), Medical University of South Carolina, reported that its business associate (BA) sent an email that contained the protected health information (PHI) of 1,758 individuals to the wrong recipients. The PHI involved included names only. The CE notified HHS, affected individuals, and the media. The employee involved was retrained.Nonames only
30
Boomerang Healthcare
CA
Healthcare Provider
1,2042023-11-07
Unauthorized Access/Disclosure
EmailNoBoomerang Healthcare, the covered entity (CE), reported that an employee inadvertently emailed an Excel spreadsheet containing the protected health information (PHI) of 1,204 patients to unauthorized individuals. The PHI involved included names, addresses, email addresses, dates of birth, phone numbers, and diagnoses. The CE notified HHS, affected individuals, and the media. In response to the breach and OCR’s investigation, the CE sanctioned the responsible employee and strengthened its administrative and technical safeguards.Nodiagnosesaddressesnamesemail addressesphone numbersdates of birth
31
Sutter HealthCA
Healthcare Provider
845,4412023-11-03
Hacking/IT Incident
Network ServerYesThe covered entity (CE), Sutter Health, reported that its business associate (BA) experienced a malware attack that affected the protected health information (PHI) of 845,441 individuals. The PHI involved included names, addresses, dates of birth, diagnoses, and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and the CE and BA implemented additional administrative, technical, and security safeguards. Staff were retrained to better protect PHI.Nodiagnoses, other treatment informationaddressesnamesdates of birthother treatment information
32
Life Generations Healthcare LLC
CA
Healthcare Provider
5,8322023-11-03
Hacking/IT Incident
EmailNoThe covered entity (CE), Life Generations Healthcare, reported that multiple employees were the subjects of an email phishing scheme that compromised the protected health information (PHI) of 5,832 individuals. The PHI involved included names, birthdates, addresses, drivers’ license and Social Security numbers, diagnoses, and financial and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards. Staff were retrained on email security.Nofinancial and other treatment informationdiagnosesaddressesdrivers’ license and Social Security numbersnamesbirthdates
33
Rebekah Children’s Services
CA
Healthcare Provider
2,0332023-11-03
Hacking/IT Incident
Network ServerNoThe covered entity (CE), Rebekah Children’s Services, reported that it experienced a cyber-attack that compromised the protected health information (PHI) of 2,033 individuals. The PHI involved included names, birthdates, diagnoses, lab results, medications, email addresses, phone numbers, Social Security and drivers’ license numbers, and other treatment information. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE updated its administrative and technical safeguards to better protect sensitive data. OCR provided technical assistance regarding the HIPAA Rules.Nodiagnoses, lab results, medicationsdrivers’ license numbersnamesemail addressesphone numbersbirthdatesother treatment informationSocial SecuritySocial Security
34
Mayo ClinicMN
Healthcare Provider
1,1522023-11-03
Unauthorized Access/Disclosure
Network ServerNoMayo Clinic, the covered entity (CE), reported that an employee inadvertently submitted the protected health information (PHI) of 1,152 individuals to an academic journal; the data was then published via the Internet. The PHI involved included names, dates of birth, lab results, medical records numbers, gender, race, and treatment information. The CE notified HHS and affected individuals. In its mitigation efforts, the CE implemented additional administrative safeguards to better protect PHI. Staff were retrained.Nonames, dates of birth, gender, racedates of birthgenderracetreatment informationmedical records numbers
35
Cadence BankMS
Business Associate
13,8622023-10-27
Hacking/IT Incident
Network ServerYesCadence Bank, the covered entity (CE), reported that its business associate (BA) experienced a cyber-attack that compromised the protected health information (PHI) of 13,862 individuals. The PHI involved included names, addresses, dates of birth, Social Security numbers, drivers’ license numbers, health insurance information, claims and financial information, and other treatment information. In its mitigation efforts, the BA implemented additional technical safeguards and provided complimentary credit monitoring services.Noclaims and financial informationaddressesdrivers’ license numbersnamesdates of birthhealth insurance informationother treatment informationSocial Security numbers
36
Pacific Clear Vision Institute
OR
Healthcare Provider
6262023-10-15
Unauthorized Access/Disclosure
EmailNoPacific Clear Vision Institute, the covered entity (CE), reported that an employee impermissibly forwarded the protected health information (PHI) of 626 individuals to her personal email account. The PHI involved included names, addresses, dates of birth, health insurance information, diagnoses, Social Security numbers, and other treatment information. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE sanctioned the employee responsible and provided complimentary credit monitoring services.Nodiagnosesaddressesnameshealth insurance informationtreatment informationSocial Security numbers
37
Brooklyn Premier Orthopedics
NY
Healthcare Provider
48,4592023-10-06
Hacking/IT Incident
Network ServerNoNo
38
Responsive Care Solutions
FL
Business Associate
5,2002023-10-05
Unauthorized Access/Disclosure
Paper/FilmsYesThe business associate (BA), Responsive Care Solutions, reported that an employee inadvertently mailed the protected health information (PHI) of 5,200 individuals. The PHI involved included names, addresses, and other treatment information. The BA notified HHS, affected individuals, and the media. In its mitigation efforts, the BA strengthened its administrative, technical, and security safeguards. Staff were retrained on the requirements to protect and secure PHI.Nonames, addresses, and other treatment informationnames, addresses, and other treatment informationnames, addresses, and other treatment information
39
Walmart Associates Health and Welfare Plan
ARHealth Plan85,9522023-10-04
Hacking/IT Incident
Network ServerYesThe covered entity (CE), Walmart Associates Health and Welfare Plan, reported that a vender of its business associates (BA) experienced a cybersecurity incident that compromised the protected health information (PHI) of approximately 85,952 individuals. The PHI involved included names, addresses, dates of birth, and health insurance information. The CE notified HHS, affected individuals, the media, and provided substitute notice. The BA and its vendor strengthened its technical safeguards to better protect sensitive data.Nonames, addresses, dates of birthnamesdates of birthhealth insurance information
40
Prospect Medical Holdings, Inc.
CA
Business Associate
1,309,0962023-09-29
Hacking/IT Incident
Network ServerYesThe covered entity (CE), Prospect Medical Holdings, reported that it experienced a ransomware incident that affected the protected health information (PHI) of 1,309,096 individuals. The PHI involved included names, dates of birth, drivers’ license and Social Security numbers, addresses, diagnoses, lab results, medications, claims and financial information, and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE offered free credit monitoring and identity theft protection services and implemented new administrative and technical safeguards.Yesfinancial information, claimsdiagnosesaddressesdrivers’ licensenamesother treatment informationSocial Security numbersmedications
41
Gillette Children's Specialty Healthcare
MN
Healthcare Provider
5422023-09-29
Hacking/IT Incident
Network ServerYesThe covered entity (CE), Gillette Children's Specialty Healthcare, reported that its business associate (BA) was the subject of a cybersecurity incident that compromised the protected health information (PHI) of 542 individuals. The PHI involved included names, medical record numbers, and other treatment information. Steps were taken to mitigate harm and protect PHI.Noother treatment informationnames, medical record numbersother treatment information
42
H3- Hope, Healing, Health Inc.
MI
Healthcare Provider
1,5862023-09-29
Hacking/IT Incident
EmailNoThe covered entity (CE), H3 - Hope, Healing, Health, reported that an employee was subjected to an email phishing scheme that compromised the protected health information (PHI) of 1,586 individuals. The PHI involved included names, addresses, dates of birth, drivers’ license and Social Security Numbers, diagnoses, lab results, medications, and health insurance information. The CE notified HHS, affected individuals, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative and technical safeguards to better protect its PHI.Nodiagnoses, lab results, medicationsaddressesdrivers’ licensenamesdates of birthhealth insurance informationSocial Security Numbersmedications
43
Mt. Graham Regional Medical Center
AZ
Healthcare Provider
35,6882023-09-29
Hacking/IT Incident
Network ServerNoMount Graham Regional Medical Center, the covered entity (CE), reported that it experienced a ransomware attack that compromised the protected health information (PHI) of 35,688 individuals. The PHI involved included names, addresses, Social Security and drivers’ license numbers, birthdates, financial information, and treatment information. In its mitigation efforts, the CE implemented additional administrative, technical, and security safeguards to better protect sensitive data.Yesfinancial informationaddressesdrivers’ license numbersnamesbirthdatestreatment informationSocial Security
44
Blue Cross Blue Shield of Texas
IL
Business Associate
3,7082023-09-22
Unauthorized Access/Disclosure
Paper/FilmsYesThe business associate (BA), Blue Cross Blue Shield of Texas, reported that an employee inadvertently mailed the protected health information (PHI) of 3,708 individuals to the wrong addresses. The PHI involved included names and health insurance information. The BA notified HHS, affected individuals, and the media In response to the breach, the BA implemented additional administrative safeguards to better protect PHI.Nonameshealth insurance information
45
Allegheny County, Pennsylvania
PA
Business Associate
1,5052023-09-22
Hacking/IT Incident
Network ServerYesAllegheny County, the business associate (BA), reported that it experienced a cyber-attack that compromised the protected health information (PHI) of 1,505 individuals. The PHI involved included names, birthdates, health insurance information, and other treatment information. The BA notified HHS, affected individuals, the media, and posted substitute notice on its website. In its mitigation efforts, the BA implemented additional administrative and technical safeguards to better protect PHI.Nonamesbirthdateshealth insurance informationother treatment information
46
Virginia Department of Medical Assistance Services
VAHealth Plan1,229,3332023-09-18
Hacking/IT Incident
Network ServerYesThe Virginia Department of Medical Assistance Services, the covered entity (CE), reported that its business associate (BA) experienced a cyber-attack that compromised the protected health information (PHI) of 1,229,333 individuals. The PHI involved included names, birthdates, Social Security and drivers’ license numbers, claims and financial information, and other treatment information. The CE notified HHS and the media. In its mitigation efforts, the CE and BA implemented additional administrative and technical safeguards to better protect PHI.


Noclaims and financial informationdrivers’ license numbersnamesbirthdatesother treatment informationSocial Security
47
Oak Valley Hospital District
CA
Healthcare Provider
284,6292023-09-15
Hacking/IT Incident
Network ServerNoOak Valley Hospital District, the covered entity (CE), reported that it experienced a cyber-attack that compromised the protected health information (PHI) of 284,629 individuals. The PHI involved included names, addresses, dates of birth, Social Security numbers, health insurance information, diagnoses, lab results, medications, and claims information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach and OCR’s investigation, the CE revised its policies and procedures, retrained its workforce members, and implemented additional technical safeguards.Nodiagnoses, lab resultsaddressesnamesdates of birthhealth insurance informationmedications, claims informationSocial Security numbersmedications
48
Nuance Communications, Inc.
MA
Business Associate
1,225,0542023-09-15
Hacking/IT Incident
Network ServerYesNuance Communications, the business associate (BA), reported that it experienced a cyber-attack that compromised the protected health information (PHI) of 1,225,054 individuals. The PHI involved included names, addresses, dates of birth, diagnoses, medications, and Social Security numbers. The BA notified HHS, affected individuals, the media, and provided substitute notice. In its mitigation efforts, the BA strengthened its administrative, technical, and security safeguards to better protect PHI.Nodiagnoses, medicationsaddressesnamesdates of birthSocial Security numbersmedicationsSocial Security numbers
49
Omnicell Specialty Pharmacy Services (OSPS)
TX
Business Associate
6612023-09-15
Hacking/IT Incident
EmailYesThe business associate (BA), Omnicell Specialty Pharmacy Services, reported that an employee was the subject of an email phishing scheme that compromised the protected health information (PHI) of 661 individuals. The PHI involved included names, dates of birth, drivers’ license numbers, addresses, Social Security numbers, medications, and other treatment information. The BA notified HHS and the affected individuals. The BA disabled the affected email account and provided complimentary credit monitoring services to the affected individuals. The BA also strengthened its administrative and technical safeguards to better protect PHI.Noaddresses, Social Security numbersdrivers’ license numbersnamesdates of birthmedications, other treatment informationSocial Security numbersmedicationsSocial Security numbers
50
Coos Health & Wellness
OR
Healthcare Provider
22,1152023-09-07
Hacking/IT Incident
Network ServerNoThe covered entity (CE), Coos Health and Wellness, reported that it experienced a cybersecurity incident that compromised the protected health information (PHI) of 22,115 individuals. The PHI involved includes names, Social Security and drivers’ license numbers, birthdates, addresses, and health insurance information. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE updated its administrative and technical safeguards. OCR provided technical assistance regarding the HIPAA Rules.Noaddressesdrivers’ license numbersnamesbirthdateshealth insurance informationSocial Security numbers, drivers’ license numbers
51
Roseman University of Health Sciences
NV
Healthcare Provider
4,6222023-09-06
Hacking/IT Incident
Network ServerNoThe covered entity (CE), Roseman University of Health Sciences, reported that it experienced a cybersecurity attack that compromised the protected health information (PHI) of 4,622 individuals. The PHI involved included names, addresses, dates of birth, drivers’ license information, Social Security numbers, diagnoses, medications, lab results, and other treatment information. The CE notified HHS, affected individuals, and the media. In response to the breach the CE implemented additional administrative and technical safeguards to better protect its PHI. OCR provided technical assistance regarding the HIPAA Rules.Nodiagnoses, medications, lab results, and other treatment informationaddressesdrivers’ license informationnamesdates of birthdiagnoses, medications, lab results, and other treatment informationSocial Security numbersmedicationsSocial Security numbers
52
Bienville Orthopaedic Specialists LLC
MS
Healthcare Provider
242,9862023-09-05
Hacking/IT Incident
Network ServerNoThe covered entity (CE), Bienville Orthopaedic Specialists, reported that it experienced a ransomware that compromised the protected health information (PHI) of 242,986 individuals. The PHI involved included names, addresses, telephone numbers, dates of birth, drivers’ license and Social Security numbers, and claims and financial information. The CE notified HHS, affected individuals, the media, and provided substitute notice on its website. In its mitigation efforts, the CE implemented additional administrative, technical, and security safeguards to better protect its PHI. Staff were retrained on the requirement to protect and secure sensitive data. OCR provided technical assistance regarding the timeliness requirements of the HIPAA Breach Notification Rule.Yesclaims and financial informationnames, addresses, telephone numbersdrivers’ license and Social Security numbersnamestelephone numbersdates of birth
53
Indiana University Health
INHealth Plan1,1912023-08-31
Hacking/IT Incident
Network ServerYesThe covered entity (CE), Indiana University Health, reported that a vendor of its business associate (BA) experienced a cyber-attack that compromised the protected health information (PHI) of 1,191 individuals. The PHI involved included names, Social Security numbers, addresses, birthdates, claims information, and other treatment information. The CE and BA notified HHS, affected individuals, the media, and provided substitute notice. In its mitigation efforts, the CE and BA strengthened its administrative and technical safeguards and provided complimentary credit monitoring services.Noaddresses, postal addresses, physical addresses, home addresses, mailing addresses, postal addressesnamesbirthdatesother treatment information, treatment
54
O'Neil Digital Solutions, LLC
CA
Business Associate
1,7222023-08-30
Unauthorized Access/Disclosure
Paper/FilmsYesThe business associate (BA), O’Neil Digital Solutions, reported that a workforce member mailed the protected health information (PHI) of 1,722 individuals to the wrong recipients. The PHI involved included names, dates of birth, and health insurance information. The BA notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the BA sanctioned the workforce member and strengthened its administrative safeguards. OCR provided technical assistance to the CE regarding the HIPAA Rules.Nonames, dates of birthdates of birthhealth insurance information
55
TTEC Healthcare Solutions
CO
Business Associate
2,9532023-08-30
Unauthorized Access/Disclosure
Network ServerYesThe business associate (BA), TTEC Healthcare Solutions, reported that one of its employees impermissibly shared access to the protected health information (PHI) of 2,953 individuals with an unauthorized individual. The PHI involved included names, Social Security numbers, addresses, drivers’ license numbers, and dates of birth. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the BA provided complimentary credit monitoring services and implemented additional administrative and technical safeguards to better protect PHI.Noaddresses, Social Security numbersdrivers’ license numbersnamesdates of birthSocial Security numbers
56
IEC Group, Inc. dba AmeriBen
ID
Business Associate
74,8842023-08-24
Unauthorized Access/Disclosure
EmailYesIEC Group dba AmeriBen, the covered entity (CE), reported that an employee inadvertently sent an email to patients that contained the protected health information (PHI) of 74,884 individuals. The PHI involved included names, financial information, and other treatment information. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE sanctioned and retrained the employee responsible for the breach and implemented new administrative safeguards.Nofinancial informationnamesother treatment information
57
The University of Massachusetts Chan Medical School
MA
Business Associate
135,3942023-08-21
Hacking/IT Incident
Network ServerYesThe covered entity (CE), The University of Massachusetts Chan Medical School, reported that it was the subject of a cyber-attack that affected the protected health information (PHI) of 135,974 individuals. The PHI involved included names, dates of births, addresses, Social Security numbers, diagnoses, medications, financial and claims information, and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards to better protect its PHI.Nofinancial and claims informationdiagnosesaddressesnamesdates of birthsother treatment informationSocial Security numbersmedications
58
Health Care Service Corporation
ILHealth Plan220,9132023-08-21
Hacking/IT Incident
Network ServerYesThe covered entity (CE), Health Care Service Corporation, reported that its business associate (BA) experienced a cyber-attack that compromised the protected health information (PHI) of 220,913 individuals. The PHI involved included names, addresses, email addresses, phone numbers, dates of birth, Social Security numbers, claims and financial information, and other treatment information. The CE notified HHS, affected individuals, and the media. OCR provided technical assistance regarding the HIPAA Privacy Rule.Noclaims and financial informationnames, addressesnamesemail addressesphone numbersdates of birthother treatment informationSocial Security numbersSocial Security numbers
59
Illinois Department of Public Health
IL
Healthcare Provider
126,0002023-08-18
Hacking/IT Incident
Network ServerNoThe covered entity (CE), Sutter Health, reported that its business associate (BA) experienced a malware attack that affected the protected health information (PHI) of 845,441 individuals. The PHI involved included names, addresses, dates of birth, diagnoses, and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and the CE and BA implemented additional administrative, technical, and security safeguards. Staff were retrained to better protect PHI.Nodiagnoses, other treatment informationaddressesnamesdates of birthother treatment information
60
Blue Cross Blue Shield of Arizona
AZHealth Plan47,4852023-08-17
Hacking/IT Incident
Network ServerYesBlue Cross Blue Shield of Arizona, the covered entity (CE), reported that a vendor of its business associate (BA) was the subject of a cybersecurity incident that compromised the protected health information (PHI) of 47,485 individuals. The PHI involved included names, dates of birth, addresses, Social Security numbers, and financial information. The CE notified HHS; the BA notified affected individuals and the media. In its mitigation efforts, the BA and vendor implemented new technical safeguards, provided affected individuals with free credit monitoring, and revised its policies and procedures. The CE implemented new security measures to prevent similar attacks from occurring in the future.Nofinancial informationaddressesnamesdates of birthSocial Security numbers
61
A-Family Dental Care Center PC
PA
Healthcare Provider
2,8002023-08-16
Unauthorized Access/Disclosure
Network ServerNoThe covered entity (CE), Medical University of South Carolina, reported that its business associate (BA) sent an email that contained the protected health information (PHI) of 1,758 individuals to the wrong recipients. The PHI involved included names only. The CE notified HHS, affected individuals, and the media. The employee involved was retrained.Nonames only
62
Performance Health Technology
OR
Business Associate
1,752,0762023-08-15
Hacking/IT Incident
Network ServerYesThe covered entity (CE), Performance Health Technology, reported that it was the victim of a hacking attack affecting the protected health information (PHI) of 1,752,076 individuals. The PHI involved include names, dates of birth, addresses, Social Security numbers, diagnoses, and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE implemented additional administrative and technical safeguards and provided complimentary credit monitoring services to affected individuals.Nodiagnoses, other treatment informationaddressesnamesdates of birthother treatment informationSocial Security numbersSocial Security numbers
63
Three Crowns Park
IL
Healthcare Provider
5162023-08-11
Hacking/IT Incident
EmailNoThe covered entity (CE), Three Crowns Park, reported that an employee was the subject of an email phishing scheme that affected the protected health information (PHI) of 516 individuals. The PHI involved included names, Social Security numbers, addresses, dates of birth, diagnoses, financial information, and other treatment information. The CE notified HHS, affected individuals, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring and implemented additional administrative and technical safeguards. Staff were retrained on email security.Nofinancial informationdiagnosesaddressesnamesother treatment information
64
United Bankshares, Inc.
DC
Business Associate
8,8012023-08-11
Hacking/IT Incident
Network ServerYesThe business associate (BA), United Bankshares, reported that it experienced a cyber-attack that compromised the protected health information (PHI) of 8,801 individuals. The PHI involved included names, addresses, dates of birth, telephone numbers, Social Security numbers, driver's license numbers, diagnoses, lab results, medications, claims and financial information, and other treatment information. The BA notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the BA installed manufacturer-provided software patches and implemented additional technical safeguards to better protect its sensitive data.Nofinancial information, claimsdiagnoses, lab resultsaddressesdriver's license numbersnamestelephone numbersdates of birthmedications, other treatment informationSocial Security numbersmedicationsSocial Security numbers
65
iTrust Wellness Group
SC
Healthcare Provider
9812023-08-10
Hacking/IT Incident
EmailNoThe covered entity (CE), iTrust Wellness Group, reported that an employee was the subject of an email phishing scheme that affected the protected health information (PHI) of 981 individuals. The PHI involved included names, phone numbers, email addresses, dates of service, claims information, and other treatment information. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the CE implemented additional administrative, technical, and security safeguards. The CE also retrained its workforce members on email security precautions.Nonames, phone numbers, email addressesemail addressesphone numbersother treatment information
66
EMS Management and Consultants Inc
NC
Business Associate
223,5982023-08-10
Hacking/IT Incident
Network ServerYesThe business associate (BA), EMS Management and Consultants, reported that it experienced a ransomware attack that compromised the protected health information (PHI) of 223,598 individuals. The PHI involved included names, addresses, dates of birth, Social Security numbers, and financial and other treatment information. The BA notified HHS, affected individuals, the media, and posted substitute notice on its website. In its mitigation efforts, the BA implemented additional administrative, technical, and security safeguards to better protect PHI.Yesfinancial and other treatment informationnames, addressesnamesdates of birthfinancial and other treatment informationSocial Security numbersSocial Security numbers
67
Madera CountyCAHealth Plan1,4462023-08-09
Unauthorized Access/Disclosure
EmailNoThe covered entity (CE) Madera County, reported that an employee of its business associate’s (BA) vendor emailed the protected health information (PHI) of 1,446 individuals to the wrong recipient. The PHI involved included names, dates of birth, health insurance information, financial information, and other identifying information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the vendor retrained its employees and implemented additional security and technical safeguards. OCR provided technical assistance regarding the HIPAA Rules.Nofinancial informationnamesdates of birthhealth insurance information
68
Virginia Dept. of Medical Assistance Services
VAHealth Plan423,8242023-08-09
Hacking/IT Incident
Network ServerYesNo
69
PCC Pediatric EHR Solutions
VT
Business Associate
5202023-08-09
Unauthorized Access/Disclosure
EmailYesThe business associate (BA), PCC Pediatric EHR Solutions, reported that an employee accidently emailed the protected health information (PHI) of 520 individuals to an unauthorized recipient. The PHI involved included names, Social Security numbers, addresses, drivers’ license numbers, dates of birth, and claims information. The BA notified HHS and affected individuals. In response to the breach, the BA implemented additional administrative safeguards and retrained its employees. OCR provided the BA with technical assistance regarding its HIPAA Breach Notification Rule requirements.Noaddresses, Social Security numbersdrivers’ license numbersnamesdates of birthSocial Security numbers
70
Sovos Compliance LLC
MA
Business Associate
18,2612023-08-08
Hacking/IT Incident
Network ServerYesThe covered entity (CE), Sovos Compliance, reported that a vulnerability was detected in its business associate’s (BA) software application that impacted the protected health information (PHI) of 18,261 individuals. The PHI involved included names, Social Security numbers, addresses, dates of birth, email addresses, and financial and claims information. The CE notified HHS, affected individuals, the media, and posted substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and the CE and BA implemented additional administrative, technical, and security safeguards to better protect PHI.Nofinancial and claims informationaddressesnamesemail addressesdates of birthSocial Security numbers
71
Redwood Coast Regional Center
CA
Healthcare Provider
1,3452023-08-07
Unauthorized Access/Disclosure
EmailNoRedwood Coast Regional Center, the covered entity (CE), reported that emails that contained the protected health information (PHI) of 1,345 individuals were sent without encryption during a network outage. The PHI involved included names, addresses, dates of birth, and other identifiers. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the CE revised its policies and procedures, retrained its workforce members, and implemented additional technical safeguards.Nonames, addresses, dates of birth, and other identifiersnamesdates of birth
72
Brigham and Women's Hospital
MA
Healthcare Provider
9872023-08-04
Unauthorized Access/Disclosure
Network ServerNoThe covered entity (CE), Brigham and Women’s Hospital, reported that graphs posted to the Internet contained a link that could expose the protected health information (PHI) of 987 individuals. The PHI involved included names, birthdates, addresses, diagnoses, lab results, medications, and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE implemented additional administrative, technical, and security safeguards. Staff were retrained to better protect PHI.Nodiagnoses, lab resultsaddressesnamesbirthdatesother treatment informationmedical recordsmedications
73
Indiana University Health
INHealth Plan21,3832023-08-04
Hacking/IT Incident
Network ServerYesThe covered entity (CE), Indiana University Health, reported that its business associate (BA) experienced a cyber-attack affecting the protected health information (PHI) of 21,383 individuals. The PHI involved included names, and health insurance and financial information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative and technical safeguards to better protect its PHI.Nofinancial informationnameshealth insurance information
74
Cognizant Technologies Solutions U.S. Corporation
TX
Business Associate
7,3132023-08-03
Hacking/IT Incident
Network ServerYesNo
75
The Health Plan of West Virginia, Inc.
WVHealth Plan1,2922023-08-01
Hacking/IT Incident
Network ServerNoThe Health Plan of West Virginia, the covered entity (CE), reported that its business associate (BA) experienced a cybersecurity incident that compromised the protected health information (PHI) of 1,292 individuals. The PHI involved included names, addresses, phone numbers, and health insurance and financial information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In its mitigation efforts, the BA implemented additional technical safeguards and provided complimentary credit monitoring services.Nofinancial informationaddressesnamesphone numbershealth insurance information
76
Allegheny County
PA
Healthcare Provider
689,6862023-07-28
Hacking/IT Incident
Network ServerNoAllegheny County, the covered entity (CE), reported that its business associate (BA) experienced a cyber-attack that compromised the protected health information (PHI) of 689,686 individuals. The PHI involved included names, addresses, phone numbers, Social Security numbers, dates of birth, drivers’ license numbers, diagnoses, claims information, and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the incident, the CE and BA strengthened its administrative, technical, and security safeguards to better protect PHI.Nodiagnoses, claims information, and other treatment informationnames, addresses, phone numbersdrivers’ license numbersnamesphone numbersdates of birthdiagnoses, claims information, and other treatment informationSocial Security numbersSocial Security numbers
77
Baylor College of Medicine
TX
Healthcare Provider
5052023-07-28
Hacking/IT Incident
Network ServerYesThe covered entity (CE), Baylor College of Medicine, reported that its business associate (BA) was the victim of a cybersecurity incident that affected the protected health information (PHI) of approximately 505 individuals. The PHI involved included names, dates of birth, Social Security numbers, and lab results. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE and BA implemented additional technical safeguards and provided complimentary credit monitoring services to affected individuals.Nonames, dates of birth, Social Security numbersdates of birthlab resultsSocial Security numbersSocial Security numbers
78
Gladden Farms Family Dentistry
AZ
Healthcare Provider
3,0852023-07-27
Hacking/IT Incident
Network ServerNoThe covered entity (CE), Gladden Farms Family Dentistry, reported that it experienced a cyber-attack that compromised the protected health information (PHI) of 3,085 individuals. The PHI involved included names, dates of birth, Social Security numbers, medication information, lab results, diagnoses, and health insurance information. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE strengthened its policies and procedures, implemented additional technical safeguards, and retrained its staff. OCR provided technical assistance regarding the HIPAA Rules.Nodiagnoses, lab resultsnamesdates of birthhealth insurance informationSocial Security numbersmedication information
79
Saint Francis Health System
OK
Healthcare Provider
18,9112023-07-26
Hacking/IT Incident
Network ServerNoNo
80
BlueCross BlueShield of Tennessee, Inc.
TN
Business Associate
2,6882023-07-25
Unauthorized Access/Disclosure
Paper/FilmsYesThe covered entity (CE), BlueCross BlueShield of Tennessee, reported that due to a computer error an employee inadvertently mailed the protected health information (PHI) of 2,688 individuals to the wrong recipients. The PHI involved included names, addresses, health insurance information, claims information, and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In its mitigation efforts, the CE strengthened its administrative and technical safeguards.Nonames, addresses, health insurance information, claims information, and other treatment informationnames, addresses, health insurance information, claims information, and other treatment informationnames, addresses, health insurance information, claims information, and other treatment informationnames, addresses, health insurance information, claims information, and other treatment information
81
Rite Aid Corporation
PA
Healthcare Provider
23,4332023-07-19
Hacking/IT Incident
Network ServerNoThe covered entity (CE), Rite Aid Corporation, reported that it experienced a cyber-attack that compromised the protected health information (PHI) of 23,433 individuals. The PHI involved included names, dates of birth, addresses, medications, and health insurance information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE installed manufacturer-provided software patches and implemented additional technical safeguards to better protect sensitive data.Noaddresses, medicationsnamesdates of birthhealth insurance information
82
Physicians Insurance A Mutual Company
WA
Business Associate
1,8522023-07-19
Hacking/IT Incident
EmailYesThe business associate (BA), Physician Insurance A Mutual Company, reported that an employee was the victim of an email phishing scheme that compromised the protected health information (PHI) of 1,852 individuals. The PHI involved included names, Social Security numbers, dates of birth, health insurance information, and other treatment information. The BA notified HHS, affected individuals, and the media. In response to the breach the BA provided complimentary credit monitoring services and implemented new administrative and technical safeguards.Nonamesdates of birthhealth insurance informationother treatment informationSocial Security numbers
83
Stephen Harkins, DDS, PC, dba: Harkins Pain & Sleep Management Group
AZ
Healthcare Provider
6,4112023-07-18
Hacking/IT Incident
Network ServerNoThe covered entity (CE), Stephen Harkins, DDS dba Harkins Pain & Sleep Management Group, reported that it experienced a ransomware attack affecting the protected health information (PHI) of 6,411 individuals. The PHI involved included names and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice on its website. In response to the breach, the CE implemented additional technical and administrative safeguards.Yesother treatment informationnamesother treatment information
84
Tahoe Forest Hospital District
CA
Healthcare Provider
1,1192023-07-17
Unauthorized Access/Disclosure
Paper/FilmsYesThe covered entity (CE), Tahoe Forest Hospital District, reported that an employee of its business associate (BA) inadvertently mailed the protected health information (PHI) of 1,119 individuals to the wrong recipients. The PHI involved included names, addresses, dates of birth, health insurance information, and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE updated its policies and retrained its employees.Nonames, addresses, dates of birth, health insurance information, and other treatment informationnames, addresses, dates of birth, health insurance information, and other treatment informationnames, addresses, dates of birth, health insurance information, and other treatment informationnames, addresses, dates of birth, health insurance information, and other treatment informationnames, addresses, dates of birth, health insurance information, and other treatment information
85
Pension Benefit Information, LLC
MN
Business Associate
1,866,6942023-07-14
Hacking/IT Incident
Network ServerYesThe business associate (BA), Pension Benefit Information, reported that its third-party vendor experienced a cyber incident that affected the protected health information (PHI) of 1,866,694 individuals. The PHI involved included names, Social Security numbers, addresses, dates of birth, and health insurance and financial information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards to better protect PHI.Nofinancial informationaddressesnameshealth insurance information
86
Care N' Care Insurance Company, Inc.
TXHealth Plan33,0322023-07-14
Hacking/IT Incident
Network ServerYesCare N' Care Insurance Company, the covered entity (CE), reported that a software application used by its business associate (BA) exposed the protected health information (PHI) of 33,032 individuals. The PHI involved included names, dates of birth, addresses, Social Security numbers, and claims and financial information. The CE notified HHS, affected individuals, and the media.Noclaims and financial informationaddressesnamesdates of birthSocial Security numbers
87
Hines Interests Limited Partnership
TXHealth Plan3,0002023-07-13
Hacking/IT Incident
Network ServerYesThe covered entity (CE), Hines Interests Limited Partnership, reported that its business associate (BA) experienced a cybersecurity attack that compromised the protected health information (PHI) of approximately 3,000 individuals. The PHI involved included names, addresses, dates of birth, diagnoses, and other treatment information. The CE notified HHS, affected individuals, and the media. In response to the breach the CE provided complimentary credit monitoring services to affected individuals.Nonames, addresses, dates of birth, diagnoses, and other treatment informationnames, addresses, dates of birth, diagnoses, and other treatment informationnames, addresses, dates of birth, diagnoses, and other treatment informationnames, addresses, dates of birth, diagnoses, and other treatment informationnames, addresses, dates of birth, diagnoses, and other treatment information
88
Molina Healthcare
CAHealth Plan7,7022023-07-11
Hacking/IT Incident
Network ServerYesMolina Healthcare, the covered entity (CE), reported that its business associate (BA) experienced a hacking attack that compromised the protected health information (PHI) of 7,702 individuals. The PHI involved included names, dates of birth, and health insurance information. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE provided complimentary identity theft protection to affected individuals. OCR provided technical assistance regarding the HIPAA Rules.Nonamesdates of birthhealth insurance information
89
Arizona State Urological Institute
AZ
Healthcare Provider
1,6262023-07-10
Unauthorized Access/Disclosure
EmailNoThe covered entity (CE), Arizona State Urological Institute, reported that an employee impermissibly sent an email containing the protected health information (PHI) of 1,626 individuals to her personal email account. The PHI involved included names, dates of birth, and treatment information. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the CE sanctioned the employee, worked with local law enforcement, conducted retraining, and added administrative safeguards. OCR provided technical assistance regarding the HIPAA Rules.Nonames, dates of birthdates of birthtreatment informationtreatment information
90
Mountain View Hospital
ID
Healthcare Provider
441,9032023-07-03
Hacking/IT Incident
Network ServerNoMountain View Hospital, the covered entity (CE), reported that it experienced a ransomware attack that compromised the protected health information (PHI) of 441,903 individuals. The PHI involved included names, addresses, dates of birth, drivers’ license and Social Security numbers, health insurance Information, lab results, medications, diagnoses, and additional treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In its mitigation efforts, the CE retrained its workforce members and implemented additional administrative and technical safeguards.Yesdiagnoses, lab resultsaddressesdrivers’ licensenamesdates of birthhealth insurance Informationadditional treatment informationSocial Security numbersmedications
91
Eastern Connecticut Health Network
CT
Healthcare Provider
9122023-07-02
Unauthorized Access/Disclosure
EmailNoThe covered entity (CE), Eastern Connecticut Health Network, reported that a workforce member sent an email disclosing the protected health information (PHI) of 912 individuals without utilizing the blind carbon copy function. The PHI involved included names and email addresses. The CE notified HHS, affected individuals, and the media. In response to the breach the CE retrained the workforce member on email protocol and the requirement to protect and secure sensitive data.Nonames and email addressesnames and email addresses
92
Health First Health Plans
FLHealth Plan7012023-06-30
Unauthorized Access/Disclosure
Paper/FilmsNoNo
93
Deanco Healthcare LLC dba Mission Community Hospital
CA
Healthcare Provider
269,8472023-06-30
Hacking/IT Incident
Network ServerNoThe covered entity (CE), Deanco Healthcare dba Mission Community Hospital, reported that it experienced a ransomware incident that affected the protected health information (PHI) of 269,847 individuals. The PHI involved included names, dates of birth, drivers’ license information, Social Security numbers, claims information, diagnoses, medications, and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE offered free credit monitoring to affected individuals and implemented additional technical safeguards to better protect its PHI. OCR provided technical assistance regarding the HIPAA Rules.Yesdiagnoses, medications, and other treatment informationdrivers’ license informationnamesdates of birthdiagnoses, medications, and other treatment informationSocial Security numbersmedicationsSocial Security numbers
94
Orrick, Herrington & Sutcliffe LLP
CA
Business Associate
342,1762023-06-30
Hacking/IT Incident
Network ServerYesThe business associate (BA), Orrick, Herrington, and Sutcliffe, reported that it experienced a cyber-attack that compromised the protected health information (PHI) of 342,176 individuals. The PHI involved included names, health insurance information, diagnoses, email addresses, phone numbers Social Security numbers, birthdates, and home addresses. The BA notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the BA provided complimentary credit monitoring services and implemented additional administrative and technical safeguards to better protect PHI.Nodiagnoseshome addressesnamesemail addressesphone numbersbirthdateshealth insurance informationSocial Security numbers
95
Arizona Health Care Cost Containment System
AZHealth Plan2,6322023-06-30
Unauthorized Access/Disclosure
Network ServerNoThe covered entity (CE), the Arizona Health Care Cost Containment System, reported that a computer programming error allowed individuals to view the protected health information (PHI) of 2,632 individuals via the Internet. The PHI involved included names, addresses, dates of birth, Social Security numbers, and other identifiers. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the strengthened its technical safeguards to better protect sensitive data. OCR provided technical assistance regarding the HIPAA Rules.Nonames, addresses, dates of birth, Social Security numbers, and other identifiersnamesdates of birthSocial Security numbers, and other identifiersSocial Security numbers
96
Imagine360PA
Business Associate
132,8072023-06-30
Hacking/IT Incident
Network ServerYesThe business associate (BA), Imagine360, reported that two of its vendors experienced a cyber-attack that compromised the protected health information (PHI) of 132,807 individuals. The PHI involved included names, addresses, dates of birth, drivers’ license and Social Security numbers, financial information, and diagnoses. The BA notified HHS, affected individuals, the media, and provided substitute notice on its website. In response to the breach, the BA offered identity protection services and the BA implemented additional technical safeguards.Nofinancial informationdiagnosesaddressesdrivers’ license and Social Security numbersnames
97
Recovery Centers of America
PA
Healthcare Provider
2,2202023-06-30
Hacking/IT Incident
Network ServerNoThe covered entity (CE), Recovery Centers of America, reported that its business associate (BA) was the victim of a ransomware attack affecting the protected health information (PHI) of 2,220 individuals. The PHI involved included names, addresses, and dates of birth. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the BA implemented additional technical safeguards.Yesnames, addresses, and dates of birthnames, addresses, and dates of birthnames, addresses, and dates of birth
98
Itasca County Health & Human Services
MN
Healthcare Provider
1,4132023-06-27
Hacking/IT Incident
EmailNoThe covered entity (CE), Itasca County Health & Human Services, reported that an employee experienced an email phishing incident that affected the protected health information (PHI) of 1,413 individuals. The PHI involved included names, Social Security and drivers’ license numbers, diagnoses, lab results, medications, addresses, birthdates, and claims and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In its mitigation efforts, the CE provided free credit monitoring services and created a toll-free number for questions or concerns. In addition, the CE implemented additional administrative and technical safeguards to better protect its PHI. Staff were retrained on email security.Nodiagnoses, lab results, medicationsdrivers’ license numbersnamesbirthdatesclaims and other treatment information
99
Tidewater Diagnostic Imaging, Ltd.
MA
Healthcare Provider
40,1952023-06-26
Hacking/IT Incident
Network ServerNoThe covered entity (CE), Tidewater Diagnostic Imaging, reported that its business associate (BA) was the victim of a hacking attack affecting the protected health information (PHI) of 40,195 individuals. The PHI involved included names, Social Security numbers, dates of service, and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In its mitigation efforts, the CE and BA implemented additional administrative, technical and security safeguards to better protect its sensitive data.Noother treatment informationnamesdates of serviceother treatment informationSocial Security numbersSocial Security numbers
100
University of Pittsburgh Medical Center
PA
Healthcare Provider
1,5332023-06-26
Hacking/IT Incident
Network ServerYesThe covered entity (CE), University of Pittsburgh Medical Center, reported that its business associate (BA) was the victim of a ransomware attack affecting the protected health information (PHI) of 1,533 individuals. The PHI involved included names, dates of birth, addresses, and Social Security numbers. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE strengthened its technical safeguards and provided complimentary credit monitoring services to affected individuals.Yesnames, dates of birth, addresses, and Social Security numbersnames, dates of birth, addresses, and Social Security numbersnames, dates of birth, addresses, and Social Security numbersnames, dates of birth, addresses, and Social Security numbers