Back to the register

Longs Peak Family Practice, P.C.

ArchivedSubmitted 12/27/2017
State
CO
Covered entity type
Healthcare Provider
Individuals affected
16,238
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Desktop Computer, Network Server
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

On November 5, 2017, Longs Peak Family Practice, the covered entity (CE), discovered that a hacker had penetrated its computer network and executed malicious code within the network before the CE could prevent it. Though the malicious code included ransomware that encrypted certain files, the CE used backup files to rebuild and restore its network without paying any ransom. The CE hired a company to perform a forensic investigation, which revealed evidence of unauthorized access to some parts of its computer system on November 5, 9, and 10, 2017, resulting in the breach of 16,238 individuals’ electronic protected health information (PHI). The types of PHI involved included demographic, financial, and clinical information. The CE provided breach notification to affected individuals, the media, and HHS. The CE also mitigated the effects of the breach by providing affected individuals with credit monitoring information and contact information should they have questions regarding the breach. Following the breach, the CE improved technical safeguards by verifying that non-essential router ports were closed, wiping and restoring affected hard drives, scanning computing devices for viruses, building a new cloud-based server environment, replacing its firewall, configuring a virtual private network, and implementing a remote monitoring and management agent/software on the CE’s devices. It also hired a new IT provider, updated its risk analysis and risk management plan, and reviewed and revised policies and procedures. In the course of its review, OCR provided the CE with technical assistance regarding risk analysis and risk management.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.