On December 20, 2017, Jemison Internal Medicine, PC (AL) discovered ransomware had encrypted files in its EMR system. Forensic investigation by Altep revealed unauthorized access via RDP, exposing PHI for 6,550 individuals including names, addresses, birthdates, driver's license numbers, SSNs, insurance information, and medical information. The CE reset passwords, implemented MFA for remote access, and updated HIPAA security policies with OCR technical assistance. Breach reported to HHS on 2018-02-16. Breached information located on Network Server.
Affected (this filing): 6,550