- State
- FL
- Covered entity type
- Healthcare Provider
- Individuals affected
- 6,092
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), FABEN Obstetrics and Gynecology, discovered on November 21, 2018, that ransomware had infiltrated electronic protected Health Information (ePHI) on its information system, affecting the demographic, clinical, financial, and health insurance information of 6,092 individuals. The CE provided timely notice of the breach to affected individuals, to the media, and to HHS. In response to the breach, the CE encrypted its computer servers, revised procedures regarding virtual private network (VPN) pathways for remote users, enhanced backup procedures, strengthened user termination procedures, and retrained employees on phishing scams and password protection. The CE is also working with its legal counsel and a third party consultant to conduct a HIPAA risk analysis, revise policies, train workforce members, and implement a risk management plan. OCR obtained assurances that the CE implemented the corrective actions listed above and performed notification obligations.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.