Back to the register

State of Alaska Department of Health and Social Services

ArchivedSubmitted 09/01/2017
State
AK
Covered entity type
Healthcare Provider
Individuals affected
501
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Desktop Computer
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

On September 1, 2017 the covered entity (CE), Alaska Department of Health and Social Services, reported that a Trojan computer virus infected two desktop computers belonging to the CE’s Office of Children’s Services (OCS) in St. Mary’s. The malware incident was caused by an employee who allowed a family member to use the desktop computer to gain access to gaming websites. The CE estimated that the breach may have affected the demographic, clinical, and financial information of more than 500 individuals, however, it is not yet known if any protected health information (PHI) was accessed due to the breach. The CE provided breach notification to HHS, the media, and affected individuals and also posted substitute notice on its website. Following the breach, the CE implemented a layered hardware and software solution to limit external excess to its computer network, system, applications, and data. It also revised policies and procedures, sanctioned the responsible employee, and retrained its workforce. OCR reviewed the CE’s HIPAA Notice of Privacy Practices Policy and obtained assurances that the CE implemented the corrective actions listed above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.