Magnolia Pediatrics (LA) reported to HHS OCR on 2019-10-09 a ransomware attack affecting 11,100 individuals. The attack encrypted ePHI stored on desktop computers, electronic medical records systems, email, and network servers. Exposed ePHI included names, dates of birth, SSNs, addresses, health insurance information, diagnoses, treatment information, and lab results — including pediatric patient records. The CE terminated its BA agreement with its IT vendor, implemented additional technical safeguards, and retrained staff. OCR obtained assurances of corrective action.
Affected (this filing): 11,100