- State
- AZ
- Covered entity type
- Healthcare Provider
- Individuals affected
- 500
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
In early August of 2016, ransomware infected Desert Care Family and Sports Medicine’s (DCFSM’s) server and encrypted all of the data contained on the server. DCFSM contacted its IT provider and Data Doctors but was unable to break one of the two encryption variants. DCFSM was also unable to recover the patient data on the server. DCFSM contacted the Casa Grande Police Department and the FBI to notify them of this incident. DCFSM is unsure how many individuals were affected by this incident but reported the breach as affecting over 500 individuals in an abundance of caution. DCFSM provided substitute and media breach notification but did not provide individual breach notification because its server was inaccessible due to the ransomware attack and it could not retrieve its patients’ contact information. In response to the breach, DCFSM added an off-site backup, retrained all of its employees, and obtained a new server. DCFSM closed its business on December 20, 2016 and as of January 1, 2017, another business is operating the practice. OCR provided DCFSM with technical assistance regarding the Security Rule risk analysis and risk management provisions.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.