ABCDEFGHIJKLMNOPQRSTUVWXYZ
1
Name of Covered EntityStateCovered Entity TypeIndividuals AffectedBreach Submission DateType of BreachLocation of Breached InformationBusiness Associate PresentWeb Description
2
Lexington Diagnostic CenterKYHealthcare Provider2981912/24/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), Lexington Diagnostic Center, reported that it experienced a hacking incident that affected the protected health information (PHI) of 29,819 individuals. The PHI involved included names, addresses, birthdates, Social Security numbers, diagnoses, lab results, and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE offered free credit monitoring to affected individuals and implemented additional administrative, technical, and security safeguards.
3
Ardon HealthORHealthcare Provider1009811/22/2024Hacking/IT IncidentEmailNo
The covered entity (CE), Ardon Health, LLC, reported that several employees were the subjects of an email phishing scheme that affected the protected health information (PHI) of 10,098 individuals. The PHI involved included names, addresses, medications, birthdates, and treatment information. The CE notified HHS, affected individuals and the media. In response to the breach and OCR’s investigation, the CE has updated its technical safeguards. OCR also provided technical assistance to the CE regarding the HIPAA Security Rule.
4
Green Castle Recovery Center DBA, Sanford Behavioral HealthMIHealthcare Provider70311/22/2024Hacking/IT IncidentEmailNo
The covered entity (CE), Green Castle Recovery Center dba Sanford Behavioral Health, reported that several employees were the subjects of an email phishing scheme that compromised the protected health information (PHI) of 703 individuals. The PHI involved included names, birthdates, addresses, drivers’ license and Social Security numbers, diagnoses/conditions, lab results, medications and other treatment information. The CE notified HHS, affected individuals and the media. In its mitigation efforts, the CE implemented additional administrative and technical safeguards to better protect its PHI. Staff were retrained in email security.
5
Village Pharmacy GroupMAHealthcare Provider58411/18/2024Hacking/IT IncidentEmailNo
The covered entity (CE), Village Pharmacy Group, reported that an employee experienced a phishing incident that affected the protected health information (PHI) of 584 individuals. The PHI involved included names, diagnoses, and other treatment information. The CE notified HHS and effected individuals. In response to the breach the CE implemented additional administrative, technical, and security safeguards. Staff were also retrained in its requirements to protect and secure PHI.
6
Option Care HealthILHealthcare Provider289711/15/2024Hacking/IT IncidentEmailNo
The covered entity (CE), Option Care Health, reported that an employee was the subject of an email phishing scheme that compromised the protected health information (PHI) of 2,897 individuals. The PHI involved included Social Security numbers, birthdates, addresses, and diagnoses. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE sanctioned and retrained the workforce member involved.
7
Missouri Department of Mental HealthMOHealthcare Provider53711/08/2024Unauthorized Access/DisclosureEmailNo
The covered entity (CE), Missouri Department of Mental Health, reported that an employee erroneously sent an unencrypted email message containing the protected health information (PHI) of 537 individuals to the wrong individuals. The PHI involved included names, Social Security numbers, addresses, and dates of birth. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE implemented additional administrative, technical, and security safeguards. Staff were retrained.
8
Universal Health CorporationVAHealthcare Provider58311/06/2024Hacking/IT IncidentEmailNo
The covered entity (CE), Universal Health Corporation, reported that an employee was subject to an email phishing scheme that affected the protected health information (PHI) of 583 individuals. The PHI involved included names, dates of birth, addresses, claims and financial information, diagnoses, lab results, medications and Social Security and drivers’ license numbers. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In its mitigation efforts, the CE implemented additional administrative, technical, and security safeguards to better protect its PHI. In addition, the CE retrained its workforce members on email security precautions and on the proper methods of identifying fraudulent email communications.
9
Embody Performance & RecoveryMOHealthcare Provider110011/04/2024Unauthorized Access/DisclosureEmailNo
10
Regence BlueCross BlueShieldORHealth Plan61010/29/2024Unauthorized Access/DisclosurePaper/FilmsYes
The covered entity (CE), Regence BlueCross BlueShield, reported that employees of its business associate (BA) mailed documents containing the protected health information (PHI) of 610 individuals to the wrong recipients. The PHI involved included names and treatment information. The CE notified HHS and affected individuals. In response to the breach, the BA sanctioned the workforce members and implemented additional administrative safeguards.
11
Southwest Colorado Mental Health Center, Inc. d/b/a Axis Health SystemCOHealthcare Provider2338510/25/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), Southwest Colorado Mental Health Center, dba Axis Health System, reported that it experienced a cyber-attack that compromised the protected health information (PHI) of 23,385 individuals. The PHI involved included clinical, demographic, and financial information. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE implemented improved technical and administrative safeguards and retrained its staff. OCR provided technical assistance to the CE.
12
Stanislaus County Behavioral Health and Recovery ServicesCAHealth Plan76710/24/2024Unauthorized Access/DisclosurePaper/FilmsNo
The covered entity (CE), Stanislaus County Behavioral Health and Recovery Services, reported that it mailed letters containing the protected health information (PHI) of 767 individuals to the wrong recipients. The PHI involved included names, addresses, and treatment information. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the CE implemented additional administrative and technical safeguards to better protect its PHI.
13
Survival Flight, Inc.AZHealthcare Provider1098910/18/2024Hacking/IT IncidentEmailNo
Survival Flight, the covered entity (CE), reported that it experienced a ransomware incident that affected the protected health information (PHI) of 10,989 individuals. The PHI involved included names, addresses, drivers’ license and Social Security numbers, dates of birth, diagnoses, financial information, and claims information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In its mitigation efforts, the CE implemented additional administrative, technical, and security safeguards.
14
OnePoint Patient CareAZHealthcare Provider174115210/14/2024Hacking/IT IncidentNetwork ServerNo
15
Seven Counties Services, Inc.KYHealthcare Provider13260910/04/2024Hacking/IT IncidentEmailNo
The covered entity (CE), Seven Counties Services, Inc., reported that multiple employees were the subjects of an email phishing incident that affected the protected health information (PHI) of 132,609 individuals. The PHI involved included names, dates of birth, addresses, Social Security numbers, diagnoses/conditions, and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE retrained its staff and implemented additional administrative, technical, and security safeguards.
16
Judge Rotenberg Educational CenterMAHealthcare Provider257910/03/2024Hacking/IT IncidentNetwork ServerNo

The covered entity (CE), Judge Rotenberg Educational Cetner, reported that it experienced a ransomware incident that affected the protected health information (PHI) of 2,579 individuals. The PHI involved included names, social security numbers, addresses, drivers’ license and government identification numbers, birthdates, and diagnoses. The CE notified HHS, affected individuals, and the media. To mitigate harm the CE offered complimentary credit monitoring and identity protection services and implemented additional technical safeguards.
17
Access Ambulatory Surgery Center, LLCNHHealthcare Provider520509/12/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), Access Ambulatory Surgery Center, reported that its business associate (BA) experienced a cyber-attack that compromised the protected health information (PHI) of 5,205 individuals. The PHI involved included names, dates of birth, Social Security numbers, claims information, and treatment information. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the CE offered free credit protection services to affected individuals.
18
Centers for Medicare & Medicaid ServicesMDHealth Plan311281509/06/2024Hacking/IT IncidentNetwork ServerYes
The covered entity (CE), Centers for Medicare and Medicaid Services, reported that a software application used by its business associate (BA) exposed the protected health information (PHI) of 3,112,815 individuals. The PHI involved included names, dates of birth, addresses, Social Security numbers, claims and health insurance information, and other treatment information. The CE notified HHS, the media, and provided substitute notice; the CE and BA notified affected individuals. In response to the breach, the CE and BA implemented additional administrative and technical safeguards to better protect PHI.
19
Guam Seventh-Day Adventist Clinic Healthcare Provider5663509/06/2024Hacking/IT IncidentEmailNo
Guam Seventh-Day Adventist Clinic, the covered entity (CE), reported that several employees were the subjects of an email phishing scheme that compromised the protected health information (PHI) of 56,635 individuals. The PHI involved included names, addresses, phone numbers, email addresses, dates of birth, financial information, drivers’ license numbers, government identification numbers, passport numbers, Social Security numbers, taxpayer identification numbers, diagnoses, and treatment and health insurance information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In its mitigation efforts, the CE implemented additional administrative and technical safeguards and retrained its staff.
20
United Way of Connecticut, Inc.CTBusiness Associate803909/03/2024Hacking/IT IncidentEmailYes
The business associate (BA), United Way of Connecticut, reported that an employee was the subject of an email phishing scheme that affected the protected health information (PHI) of 8,039 individuals. The PHI involved included names, addresses, dates of birth, medications, diagnoses, and other treatment information. The BA notified HHS, affected individuals and the media. In response to the breach, the BA offered free credit monitoring and implemented additional administrative, technical, and security safeguards. Staff were also retrained on email security.
21
Panoramic HealthAZBusiness Associate622808/28/2024Hacking/IT IncidentEmailYes
The business associate (BA), Panoramic Health, reported that an employee was the subject of an email phishing scheme that affected the protected health information (PHI) of 6,228 individuals. The PHI involved included names, dates of birth, Social Security and drivers’ license numbers, addresses, diagnoses/conditions, lab results, medications, claims and financial information, and other treatment information. The BA notified HHS, the affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards. Staff were retrained on email security precautions.
22
Okanogan Behavioral HealthCareWAHealthcare Provider2642908/23/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), Okanogan Behavioral HealthCare, reported that it experienced a ransomware attack that compromised the protected health information (PHI) of 26,429 individuals. The PHI involved included names, Social Security and drivers’ license numbers, dates of birth, diagnoses, and health insurance and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In its mitigation efforts, the CE implemented additional administrative, technical, and security safeguards to better protect its PHI. In addition, the CE retrained its workforce members on cybersecurity precautions. OCR provided technical assistance regarding the HIPAA Rules.
23
Baker Places, Inc.CABusiness Associate97108/16/2024Hacking/IT IncidentEmailYes
The covered entity (CE), Baker Places, reported that an employee was the subject of an email phishing scheme that affected the protected health information (PHI) of 971 individuals. The PHI involved included names, Social Security numbers, addresses, drivers’ license numbers, dates of birth, financial and claims information, diagnoses, medications, and other treatment information. The CE notified HHS, the affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards. Staff were retrained on email security precautions.
24
Vasinda's Around the Clock Care dba ATC Home Care CAHealthcare Provider3081908/16/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), Vasinda's Around the Clock Care dba ATC Home Care, reported that it experienced a cybersecurity incident that affected the protected health information (PHI) of 3,785 individuals. The PHI involved included names, addresses, claims information, diagnoses/conditions, lab results, medications, and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards. Staff were retrained.
25
Packaging Corporation of AmericaILHealth Plan78308/15/2024Hacking/IT IncidentNetwork ServerYes
Packaging Corporation of America, the covered entity (CE), reported that a vendor of its business associate (BA) experienced a cyber-attack that compromised the protected health information of 783 individuals. The PHI involved included names, addresses, dates of birth Social Security numbers, account identifiers, and other identifiers. The CE notified HHS and the affected individuals. In its mitigation efforts, the CE provided complimentary credit monitoring services. The BA and vendor are currently under investigation.
26
University of Connecticut Health Center Finance CorporationCTHealthcare Provider112308/13/2024Hacking/IT IncidentEmailNo
University of Connecticut Health Center Finance Corporation, the covered entity (CE), reported that an employee was the subject of an email phishing scheme that compromised the protected health information (PHI) of 1,123 individuals. The PHI involved included names, dates of birth, drivers’ license and Social Security numbers, addresses, diagnoses, and financial information. The CE notified HHS, affected individuals, and the media. In response to the breach the CE implemented additional administrative and technical safeguards. Staff were retrained on email security.
27
Julie D. Kinsler DDS LLC dba Kinsler Family DentistryINHealthcare Provider550008/12/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), Julie D. Kinsler DDS dba Kinsler Family Dentistry, reported that it was the subject of a ransomware attack that affected the protected health information (PHI) of 5,500 individuals. The PHI involved included names, addresses, dates of birth, Social Security numbers, lab results, medications, diagnoses, and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In its mitigation efforts, the CE implemented additional administrative, technical, and security safeguards to better protect PHI.
28
PG Dental d/b/a Aire Dental ArtsNYHealthcare Provider1020008/09/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), PG Dental dba Aire Dental Arts, reported that it experienced a hacking incident that affected the protected health information (PHI) of 10,200 individuals. The PHI involved included names, addresses, dates of birth, Social Security numbers, and medical information. The CE notified HHS, affected individuals, and provided media notification. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards.
29
Harborview Oral & Facial Surgery CenterMSHealthcare Provider347208/08/2024Hacking/IT IncidentNetwork ServerYes
The covered entity (CE), Harborview Oral & Facial Surgery Center reported that its business associate (BA) experienced a cybersecurity incident that compromised the protected health information (PHI) of 3,247 individuals. The PHI involved included names, addresses, dates of birth, Social Security numbers, and other treatment information. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the BA implemented additional administrative, technical, and security safeguards.
30
PRM Management Company, Inc.FLHealthcare Provider335908/02/2024Hacking/IT IncidentEmailNo
The covered entity (CE), PRM Management Company, reported that an employee was the subject of an email phishing scheme that compromised the protected health information (PHI) of 3,359 individuals. The PHI involved included names, addresses, dates of birth, claims information, diagnoses/conditions, medications, and other treatment information. The CE notified HHS, affected individuals, and provided substitute notice on its website. In response to the breach, the CE implemented additional administrative, technical, and security safeguards to better protect its PHI.
31
Providence Pediatrics Manito WAHealthcare Provider116608/01/2024Unauthorized Access/DisclosurePaper/FilmsYes
The covered entity (CE), Providence Pediatrics Manito, reported that a mailing error by an employee of its business associate (BA) resulted in the protected health information (PHI) of 1,166 individuals being mailed to incorrect addresses. The PHI involved included names and treatment information. The CE notified HHS, the affected individuals, the media, and provided substitute notice. In response to the breach, the BA implemented additional administrative safeguards and retrained workforce members to better protect PHI.
32
Advantage Orthopedic & Sports Medicine, LLPORHealthcare Provider191407/29/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), Advantage Orthopedic & Sports Medicine, reported that it experienced a cybersecurity attack that affected the protected health information (PHI) of 1,914 individuals. The PHI involved included names, addresses, dates of birth, drivers’ license information, claims and financial information, diagnoses and conditions, medications, and other treatment information. In response to the breach, the CE provided complimentary credit monitoring and implemented additional administrative and technical safeguards.
33
AMERICAN CLINICAL SOLUTIONS, LLCFLHealthcare Provider30000007/24/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), American Clinical Solutions, reported that it experienced a ransomware attack that compromised the protected health information (PHI) of 300,000 individuals. The PHI involved included names, dates of birth, addresses, and lab results. The CE notified HHS, affected individuals, the media, and provided substitute notice. The CE consequently ceased operation and the investigation was closed.
34
Allcare Medical Management IncorporatedCABusiness Associate1637807/22/2024Hacking/IT IncidentEmailYes
The business associate (BA), Allcare Medical Management, reported that an employee was the subject of an email phishing scheme that affected the protected health information (PHI) of 16,378 individuals. The PHI involved included names, dates of birth, Social Security numbers, and other demographic information. The BA notified HHS, affected individuals, the media, and posted substitute notice online. In its mitigation efforts, the BA implemented additional administrative, technical, and security safeguards to better protect its PHI. In addition, the BA retrained its workforce members on email security precautions. OCR provided technical assistance regarding the HIPAA Rules.
35
Arisa Health IncorporatedARHealthcare Provider37543607/19/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), Arisa Health, reported that it was the subject of a ransomware attack that affected the protected health information (PHI) of 375,436 individuals. The PHI involved included names, addresses, dates of birth, email addresses, Social Security numbers, medical records numbers, diagnoses/conditions, and other treatment information. The CE notified HHS, the affected individuals, the media, and provided substitute notice. In response to the breach, the CE implemented additional administrative, technical, and security safeguards. Staff were retrained.
36
Neuro Rehab Associates, Inc. d/b/a Northeast Rehabilitation Hospital NetworkNHHealthcare Provider13672407/19/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), Northeast Rehabilitation Hospital Network, reported that it experienced a cyber-attack that affected the protected health information (PHI) of 136,724 individuals. The PHI involved included names, Social Security and drivers’ license numbers, patient identification numbers, medical record numbers, diagnoses, birthdates, and health insurance and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice to its website. In response to the breach the CE provided complimentary identity theft protection services and implemented additional administrative, technical, and security safeguards to better protect its PHI.
37
Kaiser Foundation Hospitals, Northern California and The Permanente Medical Group, Inc. CAHealthcare Provider343507/15/2024Unauthorized Access/DisclosureElectronic Medical RecordNo
The covered entity (CE), Kaiser Foundation Hospitals, Northern California and The Permanente Medical Group, reported that an employee impermissibly accessed the medical records of 3,435 individuals. The protected health information (PHI) involved included names, dates of birth, addresses, email addresses, clinical information, phone numbers, and other treatment information. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE revised its policies and procedures and sanctioned the workforce member involved.
38
Aveanna Healthcare, LLCGAHealthcare Provider1048207/12/2024Unauthorized Access/DisclosureEmailNo
The covered entity (CE), Aveanna Healthcare reported that multiple employees emailed the protected health information (PHI) of 10,482 individuals to their personal email accounts. The PHI involved included names, dates of birth, health insurance information, diagnoses, lab results, medications, Social Security numbers, and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE provided complimentary credit monitoring services and strengthened its administrative, technical, and security safeguards to further protect its sensitive data.
39
New Jersey Oral & Maxillofacial Surgery NJHealthcare Provider7441307/12/2024Hacking/IT IncidentNetwork ServerNo
New Jersey Oral & Maxillofacial Surgery, the covered entity (CE), reported that it experienced a cyber-attack that compromised the protected health information (PHI) of 74,413 individuals. The PHI involved included names, addresses, dates of birth, drivers’ license and Social Security numbers, claims and financial information, diagnoses, lab results, and medications. The CE notified HHS, the affected individuals, the media, and law enforcement officials. In its mitigation efforts, the CE implemented additional technical, administrative and security safeguards.
40
Family Dynamics Counseling Services, Inc. WAHealthcare Provider437307/11/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), Family Dynamics Counseling Services, reported that its business associate (BA) impermissibly disposed of a laptop which contained the protected health information (PHI) of 4,373 individuals. The PHI involved included names, phone numbers, address, dates of birth, and other treatment information. The CE notified HHS, the affected individuals, and the media. In response to the breach, the CE terminated its business relationship with the BA and implemented new administrative and technical safeguards.
41
Janna Pharmacy LLCCAHealthcare Provider2637207/10/2024Unauthorized Access/DisclosureEmailNo
The covered entity (CE), Janna Pharmacy, reported that an employee impermissibly emailed the protected health information (PHI) of 26,372 individuals to her personal email account. The PHI involved included names, dates of birth, addresses, prescriptions, and health insurance information. The CE notified HHS and the affected individuals. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards to better protect its sensitive data.
42
Sheet Metal Workers Local Union #83 Insurance Fund and Annuity FundNYHealth Plan218407/03/2024Hacking/IT IncidentEmailNo
The covered entity (CE), Sheet Metal Workers Local Union #83 Insurance Fund and Annuity Fund, reported that an employee was the subject of an email phishing scheme that compromised the protected health information (PHI) of 2,184 individuals. The PHI involved included names, addresses, phone numbers, email addresses, dates of birth, Social Security and drivers’ license numbers, diagnoses, financial and health insurance information, medications, and claims information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE offered free credit monitoring services and implemented additional administrative, technical, and security safeguards.
43
Aultman HospitalOHHealthcare Provider689207/03/2024Hacking/IT IncidentEmailNo
Aultman Hospital, the covered entity (CE), reported that an email phishing scheme affected the protected health information (PHI) of 6,892 individuals. The PHI involved included names, medical record numbers, and claims and other treatment information. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE implemented additional administrative and technical safeguards. OCR provided technical assistance to the CE.
44
Maryville, Inc.NJHealthcare Provider2482707/03/2024Hacking/IT IncidentEmailNo
The covered entity (CE), Maryville, reported that an employee was the subject of an email phishing attack that affected the protected health information (PHI) of 24,827 individuals. The PHI involved included names, addresses, Social Security and drivers’ license numbers, dates of birth, diagnoses/conditions, lab results, mediations, and claims and treatment information. The CE notified HHS, the affected individuals, the media, and provided substitute notice. In response to the breach, the CE implemented additional administrative, technical, and security safeguards to better protect its PHI.
45
Marana Health Center, Inc.AZHealth Plan54207/02/2024Unauthorized Access/DisclosureEmailNo
The covered entity (CE), Marana Health Center, Inc., reported that a workforce member sent an email to patients containing the protected health information (PHI) of 542 individuals. The PHI involved included email addresses. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards.
46
AmeriHealth Caritas DelawareDEHealth Plan282307/01/2024Hacking/IT IncidentNetwork ServerYes
AmeriHealth Caritas Delaware, the covered entity (CE), reported that a vendor of its business associate (BA) experienced a cyber-attack that compromised the protected health information (PHI) of 2,823 individuals. The PHI involved included names, phone numbers, diagnoses, and other treatment and computer access information. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the CE, BA and its vendor, implemented additional administrative and technical safeguards to better protect sensitive data.
47
Human Technology Inc., and its affiliates TNHealthcare Provider2458007/01/2024Hacking/IT IncidentNetwork ServerNo
Human Technology Inc., the covered entity (CE), reported that it experienced a ransomware attack that compromised the protected health information (PHI) of 24,580 individuals. The PHI involved included names, addresses, dates of birth, Social Security numbers, government identification information, financial information, health insurance information and clinical information. The CE notified HHS, the affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE strengthened its technical safeguards. OCR provided technical assistance to the CE pertaining to the HIPAA Breach Notification and Security Rules.
48
SkinCure OncologyILBusiness Associate1343406/28/2024Hacking/IT IncidentEmailYes
The covered entity (CE), SkinCure Oncology, reported that it multiple employees were the subjects of an email phishing attack that affected the protected health information (PHI) of 13,434 individuals. The PHI involved included names, addresses, dates of birth, Social Security and drivers’ license numbers, claims information, diagnoses, medications, and other treatment information. The CE notified HHS, the affected individuals, the media, and provided substitute notice. In response to the breach, the CE implemented additional administrative, technical, and security safeguards.
49
Mass General Brigham Health PlanMAHealth Plan365906/28/2024Unauthorized Access/DisclosureOtherNo
Mass General Brigham Health Plan, the covered entity (CE), reported that an employee impermissibly shared her system credentials with an unauthorized individual in an effort to outsource her job duties. This breach affected the protected health information (PHI) of 3,659 individuals. The PHI involved included names, addresses, medical record numbers, dates of birth, email addresses, phone numbers, Social Security numbers, health insurance and claims information, and diagnoses. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In its mitigation efforts, the CE provided complimentary credit monitoring services and established a call center for questions or concerns. In addition, the employee was sanctioned and all staff were retrained on the requirement to protect and secure sensitive data.
50
Mass General Brigham Incorporated MAHealthcare Provider65506/28/2024Unauthorized Access/DisclosureElectronic Medical Record, OtherNo
Mass General Brigham, the covered entity (CE), reported that several employees impermissibly shared their system credentials with an unauthorized individual in an effort to outsource their job duties. This breach affected the protected health information (PHI) of 655 individuals. The PHI involved included names, addresses, medical record numbers, dates of birth, email addresses, phone numbers, Social Security numbers, health insurance and claims information, diagnoses, and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In its mitigation efforts, the CE provided complimentary credit monitoring services and established a call center for questions or concerns. In addition, the employees were sanctioned and all staff were retrained on the requirement to protect and secure sensitive data.
51
Samaritan Health Services, Inc.ORHealthcare Provider129606/27/2024Unauthorized Access/DisclosureElectronic Medical RecordNo
The covered entity (CE), Samaritan Health Services, reported that a workforce member impermissibly accessed the protected health information (PHI) of 1,296 individuals without authority. The PHI involved included names, dates of birth, addresses, Social Security numbers, claims information, diagnoses, lab results, medications, and other treatment information. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE sanctioned the workforce member and provided free credit monitoring services to affected individuals.
52
Memorial Sloan Kettering Cancer CenterNYHealthcare Provider1227406/25/2024Hacking/IT IncidentEmailNo
The covered entity (CE), Memorial Sloan Kettering Cancer Center, reported that an employee was the subject of an email phishing scheme that affected the protected health information (PHI) of 12,274 individuals. The PHI involved names, addresses, dates of birth, diagnoses, lab results, medications, and other treatment information. The CE notified HHS, the affected individuals, the media, and provided substitute notice. In response to the breach, the CE implemented additional administrative, technical, and security safeguards. Staff were retrained on email security.
53
The Mount Kisco Surgery Center LLC d/b/a The Ambulatory Surgery Center of WestchesterNYHealthcare Provider2213906/25/2024Hacking/IT IncidentEmailNo
The covered entity (CE), The Mount Kisco Surgery Center dba The Ambulatory Surgery Center of Westchester, reported that it experienced a hacking incident that affected the protected health information (PHI) of 22,139 individuals. The PHI involved included names, Social Security and drivers’ license or state identification numbers, dates of birth, diagnoses, medications, claims and financial information, and health insurance and treatment information. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards. The responsible employee was sanctioned.
54
Pinnacle Orthopaedics & Sports Medicine Specialists LLCGAHealthcare Provider110006/21/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), Pinnacle Orthopaedics & Sports Medicine Specialists, reported that it was the subject of a ransomware attack that affected the protected health information (PHI) of 1,100 individuals. The PHI involved included names, dates of birth, addresses, lab results, medications, diagnoses/conditions, and other treatment information. The CE notified HHS, the affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards. Staff were retrained to better protect its PHI.
55
Aultman HospitalOHHealthcare Provider2620606/21/2024Hacking/IT IncidentEmailNo
Aultman Hospital, the covered entity (CE), reported that an email phishing scheme affected the protected health information (PHI) of 26,062 individuals. The PHI involved included names, addresses, birthdates, Social Security numbers, health insurance information, diagnoses, and claims and other treatment information. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE implemented additional administrative and technical safeguards. OCR provided technical assistance to the CE.
56
County of Los Angeles Department of Health ServicesCAHealthcare Provider4144406/21/2024Hacking/IT IncidentEmailNo
The covered entity (CE), County of Los Angeles Department of Health Services, reported that an employee was the subject of an email phishing scheme that affected the protected health information (PHI) of 41,444 individuals. The PHI involved included names, addresses, dates of birth, drivers’ license and Social Security numbers, financial information, diagnoses and conditions, lab results, medications, and other treatment information. The CE notified HHS, the affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional technical safeguards. Staff were retrained on email security.
57
Ambulnz Holdings, LLCNYHealthcare Provider4377306/21/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), Ambulnz Holdings, reported that it experienced a cybersecurity incident that affected the protected health information (PHI) of 43,773 individuals. The PHI involved included names, Social Security numbers, addresses, drivers’ license numbers, dates of birth, diagnoses, and other treatment information. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards to better protect its PHI.
58
Access Sports Medicine & OrthopaedicsNHHealthcare Provider8804406/20/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), Access Sports Medicine & Orthopaedics, reported that it experienced a ransomware incident that affected the protected health information (PHI) of 88,044 individuals. The PHI involved included names, dates of birth, Social Security numbers, financial information and treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE offered free credit monitoring to affected individuals and implemented additional administrative, technical, and security safeguards. OCR provided technical assistance to the CE.
59
Zwanger-Pesiri RadiologyNYHealthcare Provider98506/18/2024Unauthorized Access/DisclosurePaper/FilmsNo
The covered entity (CE), Zwanger-Pesiri Radiology, reported that a computer glitch caused the protected health information (PHI) of 985 individuals to be sent to the wrong recipient. The PHI involved included names, addresses, dates of birth, and treatment information. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE implemented additional administrative and technical safeguards to better protect PHI.
60
Kaiser Foundation Health Plan of Northwest ORHealth Plan57806/14/2024Unauthorized Access/DisclosurePaper/FilmsNo
Kaiser Foundation Health Plan of the Northwest, the covered entity (CE), reported that an employee mailed the protected health information (PHI) of 578 individuals to the wrong recipients. The PHI involved included names and health insurance information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE implemented additional administrative and technical safeguards. OCR provided technical assistance regarding the HIPAA Rules.
61
Heart South Cardiovascular GroupALHealthcare Provider2057706/13/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), Heart South Cardiovascular Group experienced a ransomware attack that compromised the protected health information (PHI) of 20,577 individuals. The PHI involved included names, addresses, dates of birth, drivers’ license numbers, diagnoses, lab results, medications, health insurance information, claims and financial information, Social Security numbers, and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice on its website. In its mitigation efforts, the CE implemented new technical safeguards, and retrained workforce members. OCR provided technical assistance regarding the HIPAA Breach Notification Rule.
62
Aptihealth, Inc.NYHealthcare Provider1980506/12/2024Hacking/IT IncidentNetwork ServerYes
The covered entity (CE), Aptihealth, reported that its business associate (BA) experienced a hacking incident that affected the protected health information (PHI) of 19,805 individuals. The PHI involved included claims information, addresses, dates of birth, and names. The CE notified HHS, affected individuals, and provided media notification. In response to the breach, the CE strengthened its administrative, technical, and security safeguards.
63
Benefit Management LLCKSBusiness Associate877706/12/2024Hacking/IT IncidentEmailYes
The business associate (BA), Benefit Management, reported that an employee was the subject of an email phishing attack that affected the protected health information (PHI) of 8,777 individuals. The PHI involved included names, addresses, dates of birth, drivers’ license and Social Security numbers, claims and financial information, diagnoses, lab results, medications, and other treatment information. The BA notified HHS, affected individuals, and the media. In its mitigation efforts, the BA provided complimentary credit monitoring services and implemented additional administrative and technical safeguards.
64
Looking Glass CounselingMAHealthcare Provider273906/10/2024Unauthorized Access/DisclosureNetwork ServerNo
The covered entity (CE), Looking Glass Counseling, reported its business associate (BA) may have altered security settings on its online platform that potentially affected the protected health information (PHI) of 2,739 individuals. The PHI involved included names, email addresses, phone numbers, diagnoses, and other treatment information. The CE notified HHS and the affected individuals. In response to the breach, the CE implemented additional administrative, technical, and security safeguards to better protect PHI.
65
IACT HealthGAHealthcare Provider67606/06/2024Hacking/IT IncidentNetwork ServerYes
The covered entity (CE), IACT Health, reported that its business associate (BA) experienced a hacking incident that affected the protected health information (PHI) of 676 individuals. The PHI involved included names, addresses, dates of birth, and diagnoses/conditions. The CE notified HHS, the affected individuals, and provided substitute notice. In response to the breach, the CE and BA implemented additional administrative, technical, and security safeguards to better protect PHI.
66
Adventist Health TulareCAHealthcare Provider7080205/31/2024Hacking/IT IncidentNetwork ServerYes
Adventist Health Tulare, the covered entity (CE), reported that its business associate (BA) experienced a cyber-attack that compromised the protected health information (PHI) of approximately 70,802 individuals. The PHI involved included names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers, diagnoses, drivers’ license/state identification numbers, and health insurance information. The BA notified affected individuals and the CE notified HHS, the media, and posted a substitute notice on its website. In its mitigation efforts, the CE and BA implemented additional administrative and technical safeguards. Ultimately, the CE terminated its business relationship with the BA.
67
Boston IVF, LLCMAHealthcare Provider60405/30/2024Unauthorized Access/DisclosurePaper/FilmsNo
The covered entity (CE), Boston IVF, reported that an employee mailed billing statements that contained the protected health information (PHI) of 604 individuals to the wrong recipients. The PHI involved included names, addresses, medications, and other treatment information. The CE notified HHS and the affected individuals. In response to the breach, the CE has sanctioned the team member involved, implemented additional administrative safeguards, and retrained staff on the requirement to protect and secure sensitive data.
68
Lakeview Health Systems, LLCFLHealthcare Provider1077205/29/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), Lakeview Health Systems, reported that it experienced a ransomware incident that affected the protected health information (PHI) of 10,772 individuals. The PHI involved included names, addresses, dates of birth, Social Security numbers, drivers’ license numbers, diagnoses, prescription information, financial and health insurance information, and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE offered free credit monitoring services and implemented additional administrative, technical, and security safeguards.
69
Orchard Park Fire District EMSNYHealthcare Provider208905/29/2024Hacking/IT IncidentEmailNo
Orchard Park Fire District and Orchard Park EMS, the covered entity (CE), reported that an employee was the subject of an email phishing scheme that affected the protected health information (PHI) of 2,089 individuals. The PHI involved included names, addresses, dates of birth, Social Security numbers, drivers’ license/state ID numbers, financial and health insurance information, and other treatment information. The CE notified HHS, the affected individuals, the media, and law enforcement officials. In its mitigation efforts, the CE implemented additional technical, administrative and security safeguards.
70
Fora Health, Inc.ORHealthcare Provider156805/28/2024Hacking/IT IncidentEmailNo
The covered entity (CE), FORA Health, reported that several employees were the subjects of an email phishing attack that affected the protected health information (PHI) of 1,568 individuals. The PHI involved included names, addresses, dates of birth, Social Security numbers, diagnoses, and medications. The CE notified HHS, the affected individuals, and provided substitute notice. In response to the breach, the CE implemented additional administrative, technical, and security safeguards. Staff were retrained on email security. OCR provided technical assistance regarding the HIPAA Rules.
71
Moffitt Cancer Center and Research InstituteFLHealthcare Provider75605/24/2024Unauthorized Access/DisclosureOtherNo
The covered entity (CE), Moffitt Cancer Center and Research Institute, reported that an employee emailed the protected health information (PHI) of 756 individuals to their personal email account. The PHI involved included names, treatment information, dates of service, and health insurance information. The CE notified HHS, the affected individuals, and the media. In response to the breach, the CE sanctioned the employee involved and retrained workforce members to better protect its PHI.
72
University of Chicago Medical CenterILHealthcare Provider1033205/24/2024Hacking/IT IncidentEmailNo
The covered entity (CE), University of Chicago Medical Center, reported that multiple employees were the subjects of an email phishing attack that affected the protected health information (PHI) of 10,332 individuals. The PHI involved included names, dates of birth, Social Security numbers, passport numbers, drivers’ license or state identification numbers, financial information, diagnoses, medications, and health insurance and other treatment information. The CE notified HHS, the affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards. Staff were retrained on email security.
73
Summit Healthcare Regional Medical CenterAZHealthcare Provider90505/23/2024Unauthorized Access/DisclosureElectronic Medical RecordNo
The covered entity (CE), Summit Healthcare Regional Medical Center, reported that several employees impermissibly accessed the protected health information (PHI) of 905 individuals. The PHI involved included names, diagnoses, medications, and birthdates. The CE notified HHS, the affected individuals, and the media. In response to the breach, the CE updated its technical safeguards to better protect sensitive data. OCR provided technical assistance regarding the HIPAA Rules.
74
McLean HospitalMAHealthcare Provider223105/21/2024Unauthorized Access/DisclosureEmailNo
The covered entity (CE), McLean Hospital, reported that an employee inadvertently made an internal link that contained the protected health information (PHI) of 2,231 individuals available to anyone receiving the link via email. The PHI involved included names, email addresses, dates of birth, Social Security and drivers’ license numbers, telephone numbers, diagnoses, medications, and health insurance and other treatment information. The CE notified HHS, the affected individuals, the media, and posted substitute notice on its website. In its mitigation efforts, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards.
75
County of Los Angeles Department of Mental Health CAHealthcare Provider159805/20/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), County of Los Angeles Department of Mental Health, reported that an employee was the subject of an email phishing scheme that affected the protected health information (PHI) of 1,598 individuals. The PHI involved included names, dates of birth, Social Security Numbers. The CE notified HHS, the affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards.
76
Call 4 Health, Inc.FLBusiness Associate1043405/17/2024Hacking/IT IncidentNetwork ServerYes
The business associate (BA), Call 4 Health reported that it experienced a ransomware attack that affected the protected health information (PHI) of 10,434 individuals. The PHI involved included names, dates of birth, addresses, phones numbers, Social Security numbers, and treatment information. The BA notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the BA implemented additional administrative, technical, and security safeguards. In addition, the BA provided complimentary credit monitoring and related services to affected individuals.
77
TimeDoc, IncILBusiness Associate189405/13/2024TheftLaptopYes
The business associate (BA), TimeDoc, reported that a password-protected laptop containing the protected health information (PHI) of 1,894 individuals was stolen. The PHI involved included names, birthdates, and diagnoses. The BA notified HHS, affected individuals, and the media. In its mitigation efforts, the BA implemented additional administrative and technical safeguards to better protect PHI.
78
Children's Health CareMNHealthcare Provider2418305/10/2024Hacking/IT IncidentEmailNo
The covered entity (CE), Children’s Health Care, dba Children’s Minnesota, reported that several employees were the subjects of an email phishing attack that affected the protected health information (PHI) of 24,183 individuals. The PHI involved included names, addresses, dates of birth, health insurance information, diagnoses, and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE implemented additional administrative, technical, and security safeguards. Staff were retrained on email security.
79
Precision Medical Products Inc.CAHealthcare Clearing House109405/09/2024Hacking/IT IncidentEmailNo
The covered entity (CE), Precision Medical Products, reported that an employee was the subject of an email phishing attack that affected the protected health information (PHI) of 1,094 individuals. The PHI involved included names, email addresses, health insurance information, and financial information. The CE notified HHS and the affected individuals. In response to the breach, the CE implemented additional administrative, technical, and security safeguards. Staff were retrained on email security.
80
The Kennedy CollectiveCTHealthcare Provider85105/07/2024Hacking/IT IncidentEmailNo
The covered entity (CE), The Kennedy Collective, reported that an employee was the subject of an email phishing scheme that affected the protected health information (PHI) of 851 individuals. The PHI involved included names, addresses, Social Security numbers, dates of birth, drivers’ license information, claims information, and diagnoses. The CE notified HHS, the affected individuals, and the media. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative and technical safeguards.
81
Allina Health SystemMNHealthcare Provider71505/06/2024Unauthorized Access/DisclosureElectronic Medical RecordNo
82
Columbia University Irving Medical CenterNYHealthcare Provider2962905/06/2024Unauthorized Access/DisclosureNetwork ServerNo
The covered entity (CE), Columbia University Irving Medical Center, reported that an employee posted the protected health information (PHI) of 29,629 individuals on the Internet. The PHI involved included names, dates of birth, and a single laboratory test result. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE secured the data and provided staff additional training in its requirements to protect and secure PHI.
83
Redwood Coast Regional CenterCAHealthcare Provider2493705/03/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), Redwood Coast Regional Center, reported that it experienced a cyber-attack that compromised the protected health information (PHI) of 24,937 individuals. The PHI involved included names, dates of birth, addresses, Social Security numbers, financial and claims information, diagnoses, lab results, medications, and other treatment information. The CE notified HHS, the affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards to better protect its sensitive data.
84
Affiliated Dermatologists and Dermatologic Surgeons, P.A.NJHealthcare Provider37368005/03/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), Affiliated Dermatologists and Dermatologic Surgeons, reported that it experienced a ransomware attack that affected the protected health information (PHI) of 373,680 individuals. The PHI involved included names, dates of birth, Social Security and drivers’ license numbers, health insurance and claims information, passport numbers, and treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE offered free credit monitoring services and implemented additional administrative, technical, and security safeguards.
85
MedStar Health, Inc.MDHealthcare Provider18307905/03/2024Hacking/IT IncidentEmailNo
86
Marpai HealthNYHealthcare Provider112905/02/2024Hacking/IT IncidentEmailNo
The covered entity (CE), Marpai Health, Inc. reported that employees were the subject of an email phishing incident that affected the protected health information (PHI) of 1,129 individuals. The PHI involved included names, addresses, dates of birth, drivers’ license numbers, diagnoses, medications, claims and health insurance information, and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE implemented additional administrative, technical, and security safeguards. Staff were also retrained on email security precautions.
87
Merchants Benefit AdministrationAZHealth Plan76704/30/2024Hacking/IT IncidentEmailNo
The covered entity (CE), Merchants Benefit Administration, reported that three employees were the subjects of an email phishing attack that affected the protected health information (PHI) of 767 individuals. The PHI involved included names, Social Security numbers, and financial information. The CE notified HHS and affected individuals. In response to the breach the CE improved its technical and administrative safeguards. OCR provided technical assistance to the CE.
88
Allergy Medical Group of the North Area, Inc.CAHealthcare Provider693404/29/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), Allergy Medical Group of the North Area, reported that it experienced a cybersecurity incident that affected the protected health information (PHI) of 6,934 individuals. The PHI involved included names, dates of birth, and financial and health insurance information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In its mitigation efforts, the CE implemented additional administrative, technical, and security safeguards to better protect its PHI. In addition, the CE retrained its workforce members on security awareness precautions. OCR provided technical assistance to the CE regarding the HIPAA Rules.
89
Inland Physicians Billing ServicesCAHealthcare Clearing House7743404/27/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), Inland Physicians Billing Services, reported that experienced a ransomware attack that compromised the protected health information (PHI) of 77,434 individuals. The PHI involved included names, dates of birth, Social Security numbers, lab results, diagnoses, and health insurance and treatment information. The CE notified HHS, the affected individuals, the media, and provided substitute notice. In response to the breach and OCR’s investigation, the CE updated its administrative and technical safeguards to better protect PHI. OCR provided technical assistance regarding the HIPAA Rules.
90
OrthoConnecticut PLLCCTHealthcare Provider17874204/26/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), OrthoConnecticut, reported that it was the subject of a ransomware incident that affected the protected health information (PHI) of 178,742 individuals. The PHI involved included, names, Social Security numbers, addresses, dates of birth, diagnoses, lab results, medications, and other treatment information. The CE notified HHS, the affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards. Staff were retrained.
91
Aspire Health AllianceMAHealthcare Provider1749004/26/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), Aspire Health Alliance, reported that it experienced a ransomware incident that affected the protected health information (PHI) of 17,490 individuals. The PHI involved included named, addresses, dates of birth, Social Security and drivers’ license numbers, and financial information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE offered free credit monitoring to affected individuals and implemented additional administrative, technical, and security safeguards. OCR provided technical assistance to the CE.
92
Bay Oral Surgery & Implant CenterWIHealthcare Provider1305504/26/2024Hacking/IT IncidentEmailNo
The covered entity (CE), Bay Oral Surgery & Implant Center, reported that an employee was the subject of an email phishing attack that affected the protected health information (PHI) of 13,055 individuals. The PHI involved included names, dates of birth, addresses, email addresses, phone numbers, Social Security and drivers’ license numbers, health insurance and financial information, diagnoses, medication information, and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE implemented additional administrative, technical, and security safeguards. Staff were retrained on email security precautions.
93
County of Los Angeles Departments of Health Services and Public HealthCAHealthcare Provider25285604/25/2024Hacking/IT IncidentEmailNo
The covered entity (CE), County of Los Angeles Department of Health Services and Public Health, reported that multiple employees were the subjects of an email phishing scheme that affected the protected health information (PHI) of 252,856 individuals. The PHI involved included names, addresses, dates of birth, drivers’ license and Social Security numbers, financial information, diagnoses and conditions, lab results, medications, and other treatment information. The CE notified HHS, the affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional technical safeguards. Staff were retrained on email security.
94
Moffitt Cancer Center and Research InstituteFLHealthcare Provider2657704/24/2024Hacking/IT IncidentNetwork ServerYes
The covered entity (CE), Moffitt Cancer Center and Research Institute, learned that its business associate (BA) experienced cybersecurity incident that affected the protected health information (PHI) of 26,577 individuals. The PHI involved included names, Social Security numbers, dates of birth, claims information, diagnoses. and medications. The CE notified HHS, the affected individuals, the media, and provided substitute notice. In response to the breach, the CE and BA provided complimentary credit monitoring services and the BA implemented additional administrative, technical, and security safeguards to better protect PHI.
95
Blackstone Valley Community Health CareRIHealthcare Provider3451804/22/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), Blackstone Valley Community Health Care, reported that it was the victim of a ransomware attack affecting the protected health information (PHI) of 34,518 individuals. The PHI involved included names, social security and drivers’ license numbers, address, dates of birth, and treatment information. The CE notified HHS, affected individuals, and the media. Following the incident, the CE provided free credit monitoring and implemented additional administrative, technical, security, and physical safeguards.
96
The Georgia Institute for Plastic SurgeryGAHealthcare Provider811104/22/2024Hacking/IT IncidentNetwork ServerNo
The covered entity (CE), The Georgia Institute for Plastic Surgery, reported that it experienced a cyber-attack that affected the protected health information (PHI) of 8,111 individuals. The PHI involved included names, addresses, dates of birth, email addresses, and treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE implemented additional administrative, technical, and security safeguards. Staff were retrained on the requirement to protect and secure PHI.
97
Health First Urgent Care PLLCWAHealthcare Provider416904/22/2024Unauthorized Access/DisclosureNetwork ServerNo
The covered entity (CE), Health First Urgent Care, reported that a workforce member sent an email that contained the protected health information (PHI) of 4,169 individuals to an unauthorized recipient. The PHI involved included names and other identifiers. The CE notified HHS and the affected individuals. In its mitigation efforts, the CE sanctioned the workforce member involved and implemented additional administrative safeguards to better protect its PHI.
98
Bluebonnet Trails Community ServicesTXHealthcare Provider7616504/22/2024Hacking/IT IncidentEmailNo
The covered entity (CE), Bluebonnet Trails Community Services, reported that several employees were the subjects of an email phishing incident that affected the protected health information (PHI) of 76,165 individuals. The PHI involved included names, addresses, dates of birth, drivers’ license numbers, financial information, diagnoses/conditions, lab results, medications, and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE offered free credit monitoring services and implemented additional administrative, technical, and security safeguards. Staff were also retrained in its requirements to protect and secure PHI.
99
Advarra, Inc.MDBusiness Associate59604/19/2024Hacking/IT IncidentEmailYes
The business associate (BA), Advarra, reported that it experienced a hacking attack of an employee’s email account which compromised the protected health information (PHI) of 596 individuals. The PHI involved included names, dates of birth, addresses, Social Security numbers, financial information, and treatment information. The BA notified HHS, the affected individuals, the media, and provided substitute notice. In response to the breach, the BA provided complimentary credit monitoring and implemented additional administrative, technical, and security safeguards. Staff were retrained to better protect sensitive data.
100
Green Diamond Resource CompanyWAHealth Plan817204/19/2024Hacking/IT IncidentNetwork ServerNoGreen Diamond Resource Company reported that it experienced a ransomware attack that compromised the protected health information of 8,172 individuals. After review it was determined that the entity is not a covered entity and the case was closed.