- State
- TX
- Covered entity type
- Healthcare Provider
- Individuals affected
- 11,100
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Texas Health & Human Services Commission, detected unauthorized remote login activity from Asia to a computer server belonging to a business associate (BA), Emergence Health Network, which had been compromised by a brute force attack. The attack potentially affected the names, addresses, dates of birth, demographic, financial, clinical, and treatment information of approximately 11,000 individuals being discharged from El Paso County Jail. Following the breach, the BA retired outdated software, implemented new policies and procedures to require regular patching of software, installed a new intrusion protection detection system, updated firewalls, strengthened configurations on servers, and implemented internet protocol filtering. It also implemented a new training program for workforce members. Following OCR’s investigation, the BA updated its Breach Notification Policy.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.