CCRM Minneapolis, P.C., a Minnesota healthcare provider, reported a ransomware attack on a network server affecting PHI of 3,280 individuals. Compromised data included names, SSNs, addresses, dates of birth, driver's license numbers, claims information, diagnoses, lab results, and medication information. The CE notified HHS, the media, and affected individuals (including substitute notice), offered complimentary credit monitoring, and implemented additional administrative, physical, and technical safeguards.
Affected (this filing): 3,280