- State
- MS
- Covered entity type
- Healthcare Provider
- Individuals affected
- 64,000
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On August 2, 2016, the covered entity (CE), Urgent Care Clinic of Oxford, discovered that its server was hacked by an unauthorized third party. The CE investigated and determined that the hackers gained access to the server through an administrative account set up by the CE’s technology contractor. The types of protected health information (PHI) involved in the breach included patient names, addresses, dates of birth, driver’s licenses, social security numbers, claims information, diagnoses and conditions, lab results, and medications, affecting approximately 64,000 individuals. The CE provided breach notification to HHS, affected individuals, and the media. In response to the breach, the CE immediately shut down its server’s remote access, contacted law enforcement, hired forensic investigators and installed a new network sonic wall to protect its entire system. OCR provided technical assistance to the CE regarding risk analysis and risk management. Consequently, the CE altered its policies and procedures to include full monthly testing of its server and a new risk assessment in accordance with OCR’s Security Risk Assessment Tool. Moreover, the CE retrained its workforce on its updated policies and procedures. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.