- State
- TN
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,500
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Robert Smith DMD PC, doing business as Smith Dental, discovered on November 7, 2017, that access to its computer network server, which contains electronic protected health information (ePHI), was blocked by ransomware. The incident potentially affected the ePHI of 2,859 individuals, including demographic, clinical, financial, and health insurance information. Based on the nature and effect of the ransomware, the CE was unable to determine whether ePHI had been copied or transferred outside of the network. The CE provided breach notification to HHS, affected individuals; however, this was untimely. OCR provided substantial technical assistance regarding the CE’s breach notification obligations. In response to the breach, the CE sanctioned its manager/privacy officer for allowing security safeguards to lapse, designated a new Privacy & Security Officer, and replaced its former information technology (IT) vendor with two IT service providers. The CE substantially enhanced its information system technology and technical safeguards, adopted new HIPAA policies and procedures, and employed a new HIPAA training program. Workforce members were retrained by April 24, 2018. The CE conducted a preliminary risk assessment and planned to complete a more comprehensive analysis in the same year. OCR obtained assurances that the CE implemented the corrective actions listed above and performed its notification obligations.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.