Back to the register

Desert Care Family and Sports Medicine

ArchivedSubmitted 12/20/2016
State
AZ
Covered entity type
Healthcare Provider
Individuals affected
500
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Network Server
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

In early August of 2016, ransomware infected Desert Care Family and Sports Medicine’s (DCFSM’s) server and encrypted all of the data contained on the server. DCFSM contacted its IT provider and Data Doctors but was unable to break one of the two encryption variants. DCFSM was also unable to recover the patient data on the server. DCFSM contacted the Casa Grande Police Department and the FBI to notify them of this incident. DCFSM is unsure how many individuals were affected by this incident but reported the breach as affecting over 500 individuals in an abundance of caution. DCFSM provided substitute and media breach notification but did not provide individual breach notification because its server was inaccessible due to the ransomware attack and it could not retrieve its patients’ contact information. In response to the breach, DCFSM added an off-site backup, retrained all of its employees, and obtained a new server. DCFSM closed its business on December 20, 2016 and as of January 1, 2017, another business is operating the practice. OCR provided DCFSM with technical assistance regarding the Security Rule risk analysis and risk management provisions.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.