- State
- NM
- Covered entity type
- Healthcare Provider
- Individuals affected
- 500
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On September 29, 2016, San Juan Oncology Associates, the covered entity (CE), reported that it discovered the “Guardware@india” virus on its server. The breach affected the electronic protected health information (ePHI) of 11,383 individuals. The types of ePHI involved in the breach included demographic, financial and, clinical information. Following the breach, the CE installed a new computer server and antivirus software, completed a post risk analysis, and revised its breach notice policy to include all the elements of the media notice requirements. OCR obtained documentation of the CE’s implementation of security controls that will be continuously updated to demonstrate a culture of security compliance. OCR also provided technical assistance on breach notification and security risk analysis requirements.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.