Back to the register

Top of the World Ranch Treatment Center

ArchivedSubmitted 03/14/2023
State
IL
Covered entity type
Healthcare Provider
Individuals affected
1,980
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Email
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

The U.S. Department of Health and Human Services, Office for Civil Rights (OCR) today announced a settlement of $103,000 in an investigation of Top of the World Ranch Treatment Center (TWRTC), a substance abuse disorder treatment provider, concerning a potential violation of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule’s Risk Analysis provision. OCR enforces the HIPAA Privacy, Security, and Breach Notification Rules. The Risk Analysis provision of the Security Rule requires a regulated entity to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) held by that entity. The Breach Notification Rule requires HIPAA covered entities and their business associates to provide notification following a breach of unsecured protected health information (PHI). TWRTC detected a phishing attack, in which an unauthorized third party accessed a workforce member’s email account. TWRTC reported to OCR that it engaged a third-party forensic firm to assist with securing the account and investigating the extent of unauthorized activity. That investigation concluded that PHI for 1,980 patients was potentially accessed by the unauthorized party. OCR initiated an investigation of TWRTC’s compliance with the Risk Analysis provision. In response to OCR’s investigation, TWRTC has entered into and agrees to comply with a corrective action plan. OCR recommends that health care providers, health plans, clearinghouses, and business associates that are covered by HIPAA take the following steps to mitigate or prevent cyberthreats: • Identify where ePHI is located in the organization, including how ePHI enters, flows through, and leaves the organization’s information systems. • Integrate risk analysis and risk management into the organization’s business processes. • Ensure that audit controls are in place to record and examine information system activity. • Implement regular reviews of information system activity. • Utilize mechanisms to authenticate information to ensure only authorized users are accessing ePHI. • Encrypt ePHI in transit and at rest to guard against unauthorized access to ePHI when appropriate. • Incorporate lessons learned from incidents into the organization’s overall security management process. • Provide workforce members with regular HIPAA training that is specific to the organization and to the workforce members’ respective job duties.

Change history

  • 9/23/2026Added to OCR's archive list

Source: U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal. Records are reproduced as published; entity names and figures are OCR's.