- State
- PA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 8,193
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Northeast Philadelphia Vascular Surgeons, the covered entity (CE), reported that on March 27, 2019, an unauthorized party gained access to the protected health information (PHI) stored on its server and deployed a ransomware attack that encrypted some files. A third party investigation found a remote desktop login with an IP address originating from Russia. The attack affected 8,193 individuals. After investigation, the evidence did not find any actual opening of the files or exposure of PHI. The CE implemented multi-factor authentication for any remote access into its online environment, a mandatory virtual private network, and location restrictions for remote access. Northeast Philadelphia Vascular Surgeons also provided notification of the breach to all affected individuals.
During its investigation, OCR reviewed the newly implemented policies and procedures on uses and disclosures of PHI and the safeguarding of sensitive data. In addition, OCR provided technical guidance leading to the option of a risk analysis. The CE will conduct regular enterprise-wide risk assessments to address the risks and vulnerabilities identified in the risk analysis. OCR obtained assurances that the CE implemented the corrective actions noted.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.