- State
- AZ
- Covered entity type
- Healthcare Provider
- Individuals affected
- 11,798
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On July 5, 2017, a third party, identified as an online reporter, contacted the covered entity (CE), Adult Internal Medicine of North Scottsdale, claiming to have received demographic information for ten (10) patients from a computer hacker. While the CE was provided information that only 10 patients’ protected health information (PHI) had been breached, in an abundance of caution, the CE provided breach notification to all 11,778 patients and provided free credit monitoring. It also notified HHS and the media. The breached PHI included patients’ names, addresses, dates of birth, and social security numbers. The CE hired a cybersecurity contractor to provide 24/7 monitoring of its information technology system for unusual activity and implemented appropriate safeguards. OCR provided substantial technical assistance to the CE and obtained assurances that the CE implemented the corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.