Capital Nephrology (MD) reported to HHS on 2017-05-02 a Hacking/IT Incident affecting 4,000 individuals. The CE's EMR system and backup network server were encrypted by ransomware. Breached PHI included names and clinical information. Following the incident, the CE migrated to a cloud-based encrypted EMR, added antiviral protections, and — as a result of OCR's investigation — completed a risk analysis, developed a risk management plan, and revised its HIPAA policies and procedures. Breached info located on Electronic Medical Record and Network Server.
Affected (this filing): 4,000