Back to the register

East Valley Community Health Center, Inc.

ArchivedSubmitted 12/15/2016
State
CA
Covered entity type
Healthcare Provider
Individuals affected
65,000
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Network Server
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

On October 18, 2016, an unknown individual logged into one of the covered entity's (CE) computer servers without authorization and installed Troldesh/Shade malware, encrypting files that were stored on the server. Upon initial review, it appeared that no protected health information (PHI) was contained in the files; however, after further review the CE determined that one of the files contained claims data for 65,000 patients it had transmitted to its clearinghouse. The PHI involved in the breach included patients’ names, dates of birth, addresses, medical record numbers, health diagnosis codes and insurance account numbers. The CE provided breach notification to HHS, affected individuals, and the media. In response to OCR’s investigation, the CE revised its Security Rule policies and procedures

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.