- State
- MN
- Covered entity type
- Healthcare Provider
- Individuals affected
- 17,037
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On January 26, 2017, the covered entity (CE), Family Service Rochester, discovered that an unauthorized user had accessed its computer server, which contained the names, addresses, dates of birth, and social security numbers of approximately 17,037 patients. On the day the CE discovered the breach, it terminated all access to both its remote desktop and the compromised “programs” account. The CE also reviewed all accounts with access to the computer drive to ensure compliance with its password policy. The CE ensured that all accounts that had not been used in the past 90 days were disabled. The CE provided breach notification to HHS, affected individuals, and the media. As part of its risk analysis and risk management process, the CE also reviewed and revised its HIPAA policies and procedures. OCR obtained documented assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.