On September 5, 2017, ransomware encrypted files in East Central Kansas Area Agency on Aging's Microsoft Azure environment. The breach affected PHI of 8,000 individuals (HHS-reported count: 8,750), including names, dates of birth, addresses, Social Security numbers, and Medicaid numbers stored on a network server. The CE notified HHS, affected individuals, and the media. Remediation included engaging a cybersecurity firm, deploying cloud security software, resetting passwords, updating remote access procedures, and employee training. OCR obtained documented assurances of corrective actions.
Affected (this filing): 8,750