- State
- GA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 5,000
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Desktop Computer
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
One of the covered entity's (CE) computers was infected with malware and as a result, data on the infected computer was encrypted and made inaccessible. The CE subsequently restored the infected data. The type of protected health information (PHI) involved in the breach was clinical information and included diagnoses/conditions, lab results, medications, and other treatment information for approximately 5,000 individuals. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE retrained staff, implemented additional safeguards for secure file backup, and upgraded its antivirus software. In response to OCR’s investigation, the CE provided substitute notice of the breach. OCR provided the CE with technical assistance regarding the Security Rule including risk analysis and risk management.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.