Back to the register

Bryan County Ambulance Authority

ArchivedSubmitted 05/18/2022
State
OK
Covered entity type
Healthcare Provider
Individuals affected
14,273
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Network Server
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

Today, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced a settlement with Bryan County Ambulance Authority (BCAA), a provider of emergency medical services in Oklahoma for a potential violation of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. The settlement resolves an investigation concerning a ransomware attack on BCAA's information systems. Ransomware and hacking are the primary cyberthreats in health care. Since 2018, there has been a 264% increase in large breaches reported to OCR involving ransomware attacks. The settlement also marks the first enforcement action in OCR's Risk Analysis Initiative. This enforcement initiative was created to focus select investigations on compliance with the HIPAA Security Rule Risk Analysis provision, a key Security Rule requirement, and the foundation for effective cybersecurity and the protection of electronic protected health information (ePHI). OCR enforces the HIPAA Privacy, Security, and Breach Notification Rules, which set forth the requirements that covered entities (health plans, health care clearinghouses, and most health care providers) and business associates must follow to protect the privacy and security of protected health information. The HIPAA Security Rule establishes national standards to protect individuals' ePHI that is created, received, used, or maintained by a covered entity or business associate. It also requires appropriate administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and security of ePHI. The settlement resolves OCR's investigation concerning BCAA and this ransomware attack. In May 2022, OCR received a breach report concerning a ransomware incident that encrypted files on BCAA's network. BCAA determined that the encrypted files affected the protected health information of 14,273 patients. OCR's investigation determined that BCAA had failed to conduct a compliant risk analysis to determine the potential risks and vulnerabilities to ePHI in BCAA's systems. Under the terms of the resolution agreement, BCAA agreed to pay $90,000 and to implement a corrective action plan that will be monitored by OCR for three years. Under the corrective action plan, BCAA will take a number of steps to ensure compliance with the HIPAA Security Rule and protect the security of ePHI, including: Conducting an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to the confidentiality, integrity, and availability of its ePHI; Implementing a risk management plan to address and mitigate security risks and vulnerabilities identified in their risk analysis; Developing, maintaining, and revising, as necessary, its written policies and procedures to comply with the HIPAA Rules; and Training its workforce on its HIPAA policies and procedures.

Change history

  • 9/23/2026Added to OCR's archive list

Source: U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal. Records are reproduced as published; entity names and figures are OCR's.

We use essential cookies to run this site and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.