- State
- NV
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,128
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On October 28, 2017, the covered entity (CE), Compassion Care Hospice Las Vegas, LLC, discovered that an unknown individual gained access to its computer network and server containing 1,128 patients' protected health information (PHI), specifically demographic and clinical information. Although there was no evidence of access to or exfiltration of PHI, the CE could not rule out that PHI was at risk of compromise. Out of an abundance of caution, the CE provided breach notification to HHS, affected individuals, and the media. Following the incident, the CE changed all administrator and user credentials to its computer system, enabled intrusion prevention software and blocked all suspicious internet protocol (IP) addresses, disabled and removed all remote connection software, blocked its public IP address so that it could no longer receive inbound connections, and took both servers offline permanently. OCR obtained assurances that the CE implemented the corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.