- State
- TX
- Covered entity type
- Healthcare Provider
- Individuals affected
- 55,447
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
ABCD Pediatrics, P.A., the covered entity (CE) reported that its electronic health records system was hacked and ransomware began encrypting protected health information (PHI) stored on its servers. The PHI included patient names, addresses, dates of birth, Social Security numbers, drivers’ license information, diagnoses, medical conditions, lab results, medications, other treatments, and claims information. Approximately 55,447 individuals were affected by the breach. The CE took several corrective action steps to resolve the issue raised in the breach report. The corrective action taken included closing down remote access to terminal services and requiring workforce members to use a Virtual Private Network for remote access. The CE also conducted audits and disabled inactive user accounts, strengthened password requirements, and implemented account lockout policies. During the investigation, OCR verified that the CE implemented encryption on laptops and mobile devices. OCR provided technical assistance concerning the breach notification policies of the CE and received revised versions of those policies. The CE also revised policies regarding periodic risk analyses to update its Security Rule requirements in accordance with OCR’s technical assistance.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.