Northwest Rheumatology
ent_edac9dc1e38f1bcc000d717f
Disclosures
2
HHS OCR · State AG · 2 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
7,468
nationwide · HHS OCR AZ
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Northwest Rheumatology
- Normalized
- northwest rheumatology— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (2)newest first
- ARIZONAHHS OCRas victim2017-07-31
Northwest Rheumatology (AZ) reported to HHS on 2017-07-31 a Hacking/IT Incident (ransomware) affecting 7,468 individuals. On April 10, 2017, ransomware encrypted a limited portion of the CE's network server, potentially exposing ePHI including clinical and demographic information. In response to OCR's investigation, the CE strengthened password requirements, implemented new technical safeguards, revised business associate contracts, and retrained staff.
- New Hampshire State AGas victim2017-07-31
Northwest Rheumatology, a rheumatology clinic in Tucson, AZ, reported a ransomware incident starting April 10, 2017. Initial investigation suggested no PHI access, but on June 18, 2017, further evidence of unauthorized access was found. Forensic investigation confirmed access but could not rule out PHI exposure. Two New Hampshire residents were identified as affected. Notification letters were mailed on July 31, 2017, offering one year of credit monitoring.