- State
- AZ
- Covered entity type
- Healthcare Provider
- Individuals affected
- 244,813
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Today, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced a settlement with Assured Imaging (“Assured”) on behalf of Assured Imaging Affiliated Covered Entities, a medical imaging and screening service provider, concerning a potential violation of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. Assured is a covered entity that provides services in Arizona, California, Georgia, , New Mexico, Nevada, New York, New Jersey, Pennsylvania, Texas, Oregon, and Washington .
The settlement resolves an investigation that OCR initiated after receiving a breach report that Assured filed on August 27, 2020. Assured reported that on May 19, 2020, Assured discovered that a server on its network was infected with ransomware, impacting the PHI of over 244,000 patients. Affected PHI included patient names, addresses, dates of birth, diagnosis and conditions, lab results, medications, and treatment information. OCR’s investigation determined that Assured had impermissibly disclosed PHI, failed to conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to the confidentiality, integrity, and availability of its ePHI, and failed to timely notify affected individuals of the breach.
Under the terms of the resolution agreement, Assured agreed to implement a corrective action plan that will be monitored by OCR for two years and paid $375,000 to OCR. Under the corrective action plan, Assured has committed to take steps to ensure compliance with the HIPAA Security Rule and protect the security of ePHI, including:
• Conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to the confidentiality, integrity, and availability of its ePHI;
• Develop and implement a risk management plan to address and mitigate security risks and vulnerabilities identified in its risk analysis to a reasonable and appropriate level;
• Develop, maintain, and revise, as necessary, written policies and procedures to comply with the HIPAA Privacy, Security and Breach Notification Rules; and
• Provide annual training for all workforce members with access to ePHI.
OCR recommends that health care providers, health plans, health care clearinghouses, and business associates that are covered by HIPAA take the following steps to mitigate or prevent cyber-threats:
• Identify where ePHI is located in the organization, including how ePHI enters, flows through, and leaves the organization’s information systems.
• Periodically conduct, and update as needed, a risk analysis and develop and implement a risk management plan to address identified risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.
• Ensure audit controls are in place to record and examine information system activity.
• Implement regular review of information system activity.
• Utilize mechanisms to authenticate information to ensure only authorized users are accessing ePHI.
• Encrypt ePHI in transit and at rest to guard against unauthorized access to ePHI when appropriate.
• Incorporate lessons learned from incidents into the organization’s overall security management process.
• Provide workforce members with regular HIPAA training that is specific to the organization and to the workforce members’ respective job duties.
Change history
- 9/23/2026Added to OCR's archive list
Source: U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal. Records are reproduced as published; entity names and figures are OCR's.