Back to the register
Bryan Myers, MD PC, Ashley DeWitt, DO PC, Michael Nobles, MD PC
ArchivedSubmitted 12/30/2016
- State
- TN
- Covered entity type
- Healthcare Provider
- Individuals affected
- 13,150
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Premier Women’s Health Center, discovered on November 2, 2016, that its EHR server had been infected with malware, affecting the electronic protected health information (ePHI) of 13,150 individuals. Information stored on the affected server included names, addresses, dates of birth, social security numbers, diagnoses/conditions, lab results, medications and other treatment information. The CE was able to disconnect the server from the network before any data was exfiltrated. The CE provided breach notification to HHS, to affected individuals, and to the media. OCR provided technical assistance to the CE regarding media notice and the performance of risk analyses. In response to the breach, the CE improved technical safeguards on its information system including upgrading firmware and software. The CE also implemented all new HIPAA policies and re-trained its workforce in May 2017. It initiated an enterprise-wide risk analysis through the aid of legal counsel. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.