On January 25, 2014, Valley View Hospital Association (Glenwood Springs, CO) discovered malware had infected 172 computer workstations. On 90 of those workstations, the malware captured screen shots of ePHI belonging to 5,415 individuals and stored them as encrypted hidden files. Exposed data included names, SSNs, demographic information, and credit card data. The CE deployed anti-virus software, notified HHS, affected individuals, and media. OCR's investigation led to revised ePHI safeguarding procedures and an updated risk analysis and management plan. Breached information located on Desktop Computer and Laptop.
Affected (this filing): 5,415