- State
- KY
- Covered entity type
- Healthcare Provider
- Individuals affected
- 84,681
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Desktop Computer, Email, Laptop, Network Server, Other Portable Electronic Device
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The FBI notified the covered entity (CE), OH Muhlenberg, LLC, on September 16, 2015, that its information system had been infected with malware known as “QuakBot.” Based on the CE’s internal investigation, it determined that the malware may have been present on its system as early as January 1, 2012 and may have affected its entire patient database of 84,506 patients. The types of protected health information (PHI) involved included names, dates of birth, addresses, phone numbers, driver’s licenses/state identification information, social security numbers, credit card/bank account numbers, health insurance information, and clinical information. In response to the breach, the CE decommissioned affected computers, replaced older computer hardware, implemented revised policies and procedures, improved antivirus protection and provided security awareness training to its workforce. The CE provided breach notification to HHS, to affected individuals, to the media and on its website. OCR obtained assurances that the CE implemented the corrective actions listed above
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.