- State
- FL
- Covered entity type
- Business Associate
- Individuals affected
- 502,416
- Business associate present
- Yes
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
A business Associate (BA), Health Management Concepts, Inc., discovered on July 16, 2018, that ransomware had encrypted data on a secure File Transfer Protocol (sFTP) computer server, including electronic protected health information (ePHI). While the BA determined that the ransomware incident resulted in a low probability of compromise to ePHI and no reportable breach occurred, ePHI for one covered entity (CE), Inlandboatmen’s Union of the Pacific National Benefit Fund, was inadvertently disclosed to the ransom attacker during negotiations for the decryption key. The breached ePHI included the names, Social Security numbers, and health insurance plan information of 2,452 individuals. After technical assistance from OCR, the BA provided breach notification on behalf of the CE. In response to the breach, the BA reset passwords, installed a new computer server with a new IT host, reconfigured firewall and remote access procedures, revised its written breach notification procedures, and engaged a new data backup service. In response to technical assistance from OCR, the BA completed a risk analysis in June 2019 to meet the standards of the Security Rule. OCR obtained assurances that the BA implemented the corrective actions listed above and performed notification obligations on behalf of the CE.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.