- State
- TN
- Covered entity type
- Healthcare Provider
- Individuals affected
- 65,000
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On February 27, 2017, the covered entity (CE), Primary Care Specialists, Inc., experienced a cyber-attack in which an unauthorized user accessed the CE’s system by hacking a user account that had been granted administrative privileges. The CE initially reported that approximately 65,000 individuals were affected and the protected health information (PHI) involved included names, addresses, dates of birth, drivers’ license numbers, social security numbers, claims information, diagnoses, lab results, and medications. However, after completing its investigation into the incident, which included a forensic analysis and the assistance of a third party IT service partner, the CE concluded that there was a low probability of compromise to any PHI. The CE provided OCR with documentation of its investigation and conclusion. To prevent a similar type of attack in the future, the CE reset all passwords, implemented new password requirements, reviewed and restructured domain administrator groups, disabled all external remote desktop access, retired the computer server from which the attacker gained access to the CE’s system and deployed additional malware protections. The CE also instituted quarterly security reviews and revised its annual HIPAA training program. Additionally, though the CE ultimately determined there was no reportable breach, it provided individual notification of the incident to its current patients, HHS, the media, and on its website. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.