- State
- KY
- Covered entity type
- Healthcare Provider
- Individuals affected
- 5,335
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Estill County Chiropractic, discovered that an unauthorized user installed malicious software (ransomware) on its computer system that encrypted 5,335 patients’ files. An investigation revealed that the hacker was able to gain access to the CE’s server using the administrative credentials of its electronic medical records vendor. The types of PHI involved in the incident included patients’ names, addresses, phone numbers, email addresses, dates of birth, social security numbers, provider notes, health plan and claims numbers, clinical information, and health diagnoses. The CE provided breach notification to HHS, affected individuals, and the media. The CE immediately disconnected its server and workstations, hired outside counsel, and consulted forensic investigators. Further, the CE purchased and installed a new server and installed a new version of its electronic medical record software with strengthened safeguards. OCR provided technical assistance to the CE regarding business associate (BA) agreements with vendors, and the CE provided OCR with an updated BA agreement. The CE also retrained its workforce and updated its HIPAA policies and procedures. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.