Back to the register

Northeast Philadelphia Vascular Surgeons, P.C.

ArchivedSubmitted 03/27/2019
State
PA
Covered entity type
Healthcare Provider
Individuals affected
8,193
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Network Server
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

Northeast Philadelphia Vascular Surgeons, the covered entity (CE), reported that on March 27, 2019, an unauthorized party gained access to the protected health information (PHI) stored on its server and deployed a ransomware attack that encrypted some files. A third party investigation found a remote desktop login with an IP address originating from Russia. The attack affected 8,193 individuals. After investigation, the evidence did not find any actual opening of the files or exposure of PHI. The CE implemented multi-factor authentication for any remote access into its online environment, a mandatory virtual private network, and location restrictions for remote access. Northeast Philadelphia Vascular Surgeons also provided notification of the breach to all affected individuals. During its investigation, OCR reviewed the newly implemented policies and procedures on uses and disclosures of PHI and the safeguarding of sensitive data. In addition, OCR provided technical guidance leading to the option of a risk analysis. The CE will conduct regular enterprise-wide risk assessments to address the risks and vulnerabilities identified in the risk analysis. OCR obtained assurances that the CE implemented the corrective actions noted.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.