- State
- MA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 16,276
- Business associate present
- Yes
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
A business associate (BA), Business and Professional Exchange, that provided the covered entity (CE) with 24-hour telephone answering services, experienced a ransomware incident affecting their computer network servers. The breach involved the electronic protected health information (ePHI) of approximately 16,276 individuals, including demographic and clinical information. The CE provided breach notification to HHS, affected individuals, and the media. OCR reviewed the BA agreement between the BA and CE and it appears to comply with the requirements of the HIPAA Rules. Following this incident, the parties no longer have a business relationship.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.