- State
- GA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 36,496
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Vascular Surgical Associates, discovered that on September 13, 2016, it had experienced a distributed denial of services attack. Upon investigation, it was determined that unauthorized third parties were able to gain access into the CE’s computer server through an administrative account set up by its electronic health records (EHR) system vendor and to enter the server and obtain PHI undetected after installing software to prevent the CE from seeing the activity. The types of PHI on the CE’s server included patients' names, addresses, dates of birth, and health diagnoses and conditions. The server contained PHI for approximately 36,496 individuals. The CE provided breach notification to HHS, affected individuals, and the media. In response to the breach, the CE immediately terminated the unauthorized third parties’ access to its server, changed and strengthened passwords and contacted law enforcement. Additionally, the CE strengthened the security of its server by implementing Sonicwall protection, antivirus software, and Secure Sockets Layer virtual private network, and conducting daily log reviews looking for anomalies. Furthermore, the CE rebuilt its network, including its EHR system, retrained its workforce, and strengthened its HIPAA policies and procedures. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.