- State
- SD
- Covered entity type
- Healthcare Provider
- Individuals affected
- 13,000
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Siouxland Anesthesiology, the covered entity (CE), reported it was the subject of a criminal malware attack. The CE reported that hackers infiltrated one of its computer servers and installed malware that left patients’ electronic protected health information (ePHI) vulnerable to unauthorized access. The exposed ePHI included patients’ names, addresses, dates of birth, and, in some cases, Social Security numbers. The breach affected approximately 13,000 individuals. Following the breach report to the individuals, media and HHS, the CE investigated the incident and provided affected individuals with credit monitoring information and contact information should they have questions regarding the breach. In response to the breach and OCR’s review, the CE took a number of actions to address and mitigate the effects of the breach including: disabling the compromised server and replacing it with a new server; examining all work stations to ensure they were secure; and, establishing user controls and updating its password management procedures. In the course of its review, OCR provided the CE with technical assistance regarding necessary changes to its policies and procedures, and the requirements to conduct periodic thorough enterprise wide risk analyses and to review and update its risk management process.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.