- State
- TN
- Covered entity type
- Healthcare Provider
- Individuals affected
- 566,236
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), MSK Group PC, discovered on May 7, 2018, that ransomware blocked access to its computer servers which the contained electronic protected health information (ePHI) of 566,236 former and current patients. The ePHI potentially affected included demographic, clinical, and health insurance information. The CE was unable to determine whether ePHI had been copied or transferred outside of the network. The CE timely performed its breach notification obligations. In response to the breach, the CE engaged an information technology firm to continuously monitor its information systems and respond to suspicious activity. The CE also retrained its workforce and implemented substantial technical safeguards, including upgrading firewall protections, reconfiguring servers, and restricting remote access. OCR obtained assurances that the CE implemented the corrective actions listed above and performed its notification obligations.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.