- State
- CT
- Covered entity type
- Healthcare Provider
- Individuals affected
- 23,578
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Desktop Computer, Electronic Medical Record, Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On November 29, 2018, Dr. DeLuca, Dr. Marciano, and Associates, P.C., the covered entity (CE), were subjected to a cyber-attack that affected the electronic protected health information (ePHI) of 23,578 individuals. The PHI was contained on two servers. The CE reported that clinical, demographic, and financial information was affected in this incident. However, later the investigation confirmed that one of the servers had been encrypted and the PHI on that server was not involved. The PHI on the unencrypted server contained only patient names and medical imaging. Following the breach, the CE provided breach notification to the affected individuals and to the media. The CE is taking the following actions to improve its security posture: conducting a risk analysis and implementing a risk management plan, upgrading its firewall and antivirus software, appointing a new Privacy Officer, and providing additional HIPAA training to all of its workforce members.
OCR provided technical assistance to the CE regarding conducting a thorough enterprise-wide risk analysis. We also provided guidance on the development and implementation of written policies and procedures as required by the HIPAA Rules.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.