Back to the register
State of Alaska Department of Health and Social Services
ArchivedSubmitted 09/01/2017
- State
- AK
- Covered entity type
- Healthcare Provider
- Individuals affected
- 501
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Desktop Computer
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On September 1, 2017 the covered entity (CE), Alaska Department of Health and Social Services, reported that a Trojan computer virus infected two desktop computers belonging to the CE’s Office of Children’s Services (OCS) in St. Mary’s. The malware incident was caused by an employee who allowed a family member to use the desktop computer to gain access to gaming websites. The CE estimated that the breach may have affected the demographic, clinical, and financial information of more than 500 individuals, however, it is not yet known if any protected health information (PHI) was accessed due to the breach. The CE provided breach notification to HHS, the media, and affected individuals and also posted substitute notice on its website. Following the breach, the CE implemented a layered hardware and software solution to limit external excess to its computer network, system, applications, and data. It also revised policies and procedures, sanctioned the responsible employee, and retrained its workforce. OCR reviewed the CE’s HIPAA Notice of Privacy Practices Policy and obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.