Back to the register

University of Mississippi Medical Center

ArchivedSubmitted 07/07/2017
State
MS
Covered entity type
Healthcare Provider
Individuals affected
7,492
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Electronic Medical Record, Network Server
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

The covered entity (CE), the University of Mississippi Medical Center, discovered that data on a segregated network server had been encrypted by ransomware on May 7, 2017. After an internal investigation, it was determined that the server contained data from a previous electronic medical record which had last been used around May 2016. The breach affected the demographic, clinical, and health insurance information of 7,492 individuals. The CE provided breach notification to HHS, affected individuals, and the media, and on its website. At the time of the breach and investigation, the CE was under a Corrective Action Plan (CAP) with OCR and being monitored by OCR's Pacific Region. The CE took voluntarily corrective action in response to the breach and as required under the CAP, including substantially revising its security policies and the conducing an enterprise-wide risk analysis. At the time of this submission, the CE was working with an internal monitor to ensure compliance with the CAP provisions. OCR obtained assurances that the CE implemented the corrective actions listed above and performed its notification obligations.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.