Estill County Chiropractic, a Kentucky chiropractic provider, reported to HHS OCR on 2017-03-16 that ransomware was deployed on its server, encrypting files containing PHI of 5,335 patients. The attacker gained access using administrative credentials belonging to the covered entity's electronic medical records (EMR) vendor — a third-party/business-associate credential compromise. PHI exposed included names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers, provider notes, health plan and claims numbers, clinical information, and diagnoses. The CE disconnected affected systems, engaged outside counsel and forensic investigators, replaced the server, deployed a new EMR with stronger controls, executed an updated BA agreement, retrained staff, and revised HIPAA policies. OCR provided technical assistance and obtained assurances of corrective action.
Affected (this filing): 5,335