- State
- VA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 5,454
- Business associate present
- Yes
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On November 17, 2016, after receiving information from law enforcement, the covered entity (CE) determined that its business associate (BA), Medstreaming, experienced a cybersecurity incident impacting 5,454 records of vascular and thoracic patients seen at the CE between 2012 and 2015. The data may have contained demographic and clinical information. The CE provided breach notification to HHS, affected individuals, and the media. Both the CE and the BA hired system forensic teams to look for exfiltration of data and evidence of inappropriate access to the system. The CE determined that the files contained PHI from other sources, suggesting that the breach came from an outside vendor. Despite this information, the CE rebuilt its Medstreaming platform, engaged a cybersecurity forensics firm to perform complete network compromise assessment, and improved technical safeguards, including monitoring the internet-facing cybersecurity posture of high-risk third party service providers and installing tools to block malware callback activity. OCR reviewed a copy of the BA Agreement, the notification of the breach to the affected individuals, as well as the security measures implemented to address risks and vulnerabilities. OCR obtained assurances that the CE implemented the corrective actions listed.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.