Providence Medical Institute faced a ransomware attack in April 2018, with 85,000 individuals' electronic protected health information (ePHI) compromised. This series of ransomware attacks resulted in the encryption of servers containing ePHI. The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) found two violations of the HIPAA Security Rule, including lack of a business associate agreement and insufficient access policies. This led to a $240,000 civil penalty against Providence, underlining the necessity for robust cybersecurity measures in the healthcare sector to protect patient data.
"id": "pro506031825",
"linkid": "providence-hospital_2",
"type": "Ransomware",
"date": "10/2024",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"