Back to the register

Harrisburg Endoscopy and Surgery Center

ArchivedSubmitted 04/28/2017
State
PA
Covered entity type
Healthcare Provider
Individuals affected
9,092
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Network Server
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

Harrisburg Endoscopy and Surgery Center, the covered entity (CE), filed a separate breach report that was also filed for Harrisburg Gastroenterology LTD concerning the same ransomware and subsequent investigation. The CE discovered that an unauthorized party obtained credentials allowing access to the CE’s record systems. The breach affected the protected health information (PHI) of 9,092 individuals for this CE, a subset of 93,323 for both CEs. The types of PHI involved included demographic and clinical information, health insurance numbers and social security numbers. With the assistance of a forensic business associate (BA), the CE deactivated the compromised domain account and reset all account passwords. The CE retained a forensic information technology (IT) consulting firm which conducted a comprehensive assessment to identify risks and vulnerabilities and to provide assistance with the implementation of new technical safeguards. The CE contracted with a new IT consulting firm, replaced its existing computer network firewall with one that has enhanced monitoring and intrusion detection/prevention capabilities and created an additional layer of computer server security. The CE also reviewed all user accounts and limited permissions on certain accounts to restrict standard users from making unapproved changes or installing unauthorized software on their devices. OCR reviewed the CE’s policies and procedures on uses and disclosures of PHI and safeguards. During the investigation, OCR reviewed a copy of the CE’s 2016 risk analysis in place at the time of the incident, and its finalized 2017 risk analysis, the BA agreement with the vendor, as well as the security measures implemented to address risks and vulnerabilities. OCR obtained assurances that the CE implemented the corrective actions listed above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.