Back to the register

Jemison Internal Medicine, PC

ArchivedSubmitted 02/16/2018
State
AL
Covered entity type
Health Plan
Individuals affected
6,550
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Network Server
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

On December 20, 2017, Jemison Internal Medicine, P.C., the covered entity (CE), discovered that files in its electronic medical records (EMR) were encrypted by ransomware. Through its contracted forensic investigator, Altep, the CE found that there was unauthorized access through its remote desktop protocol (RDP) service and that the protected health information (PHI) for 6,550 individuals was exposed. The exposed PHI included names, addresses, birthdates, driver’s license information, social security numbers, insurance information, and medical information. In response to the breach, the CE reset all system passwords, implemented multifactor authentication for all remote access, and reviewed its HIPAA policies and procedures. As a result of this review and OCR’s technical assistance, the CE implemented new policies and procedures regarding its security and risk management program. The CE provided breach notification to HHS, the affected individuals, and the media, and posted substitute notice on its website. OCR obtained assurances that the CE implemented the corrective actions noted above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.