- State
- TX
- Covered entity type
- Healthcare Provider
- Individuals affected
- 15,761
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Institute for Women’s Health, the covered entity (CE), reported that a keylogger virus on its computer network captured information keyed into the CE’s system for more than a month. The protected health information (PHI) of 15,761 individuals was involved in the breach. The types of PHI included demographic, financial, and clinical information. The CE notified the affected individuals and the media. During the investigation, OCR provided technical assistance concerning a risk analysis which the CE subsequently provided. Based on further technical assistance from OCR, the CE updated and implemented technical and procedural changes to prevent a similar event from occurring in the future and retrained its staff.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.