- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 65,000
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On October 18, 2016, an unknown individual logged into one of the covered entity's (CE) computer servers without authorization and installed Troldesh/Shade malware, encrypting files that were stored on the server. Upon initial review, it appeared that no protected health information (PHI) was contained in the files; however, after further review the CE determined that one of the files contained claims data for 65,000 patients it had transmitted to its clearinghouse. The PHI involved in the breach included patients’ names, dates of birth, addresses, medical record numbers, health diagnosis codes and insurance account numbers. The CE provided breach notification to HHS, affected individuals, and the media. In response to OCR’s investigation, the CE revised its Security Rule policies and procedures
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.