- State
- AZ
- Covered entity type
- Healthcare Provider
- Individuals affected
- 14,236
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Francisco Jaume, D.O. the covered entity (CE), reported a breach of 14,246 patients’ protected health information (PHI) when it suffered a ransomware (malware) attack starting on August 22, 2016. The types of PHI involved included patients’ names, addresses, medical information, and social security numbers. The CE provided breach notification to affected individuals, the media, and HHS. Immediately after discovering the breach, the CE worked to regain control of its data and investigated the incident using forensic analysis. As a result of the incident and OCR’s investigation, the CE implemented additional safeguards, such as regular remote monitoring and monthly reporting of intrusion activity, anti-virus management, changed/strengthened system passwords, and revised backup processes. In addition, the CE trained staff and revised its HIPAA policies and procedures. OCR obtained assurances that the CE implemented the corrective actions above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.