- State
- AL
- Covered entity type
- Health Plan
- Individuals affected
- 6,550
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On December 20, 2017, Jemison Internal Medicine, P.C., the covered entity (CE), discovered that files in its electronic medical records (EMR) were encrypted by ransomware. Through its contracted forensic investigator, Altep, the CE found that there was unauthorized access through its remote desktop protocol (RDP) service and that the protected health information (PHI) for 6,550 individuals was exposed. The exposed PHI included names, addresses, birthdates, driver’s license information, social security numbers, insurance information, and medical information. In response to the breach, the CE reset all system passwords, implemented multifactor authentication for all remote access, and reviewed its HIPAA policies and procedures. As a result of this review and OCR’s technical assistance, the CE implemented new policies and procedures regarding its security and risk management program. The CE provided breach notification to HHS, the affected individuals, and the media, and posted substitute notice on its website. OCR obtained assurances that the CE implemented the corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.