Back to the register

MSK Group

ArchivedSubmitted 05/22/2018
State
TN
Covered entity type
Healthcare Provider
Individuals affected
566,236
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Network Server
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

The covered entity (CE), MSK Group PC, discovered on May 7, 2018, that ransomware blocked access to its computer servers which the contained electronic protected health information (ePHI) of 566,236 former and current patients. The ePHI potentially affected included demographic, clinical, and health insurance information. The CE was unable to determine whether ePHI had been copied or transferred outside of the network. The CE timely performed its breach notification obligations. In response to the breach, the CE engaged an information technology firm to continuously monitor its information systems and respond to suspicious activity. The CE also retrained its workforce and implemented substantial technical safeguards, including upgrading firewall protections, reconfiguring servers, and restricting remote access. OCR obtained assurances that the CE implemented the corrective actions listed above and performed its notification obligations.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.