25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Ransomware Attack on New York Medical Group Impacts 330K Patients

The New York medical group practice, Orthopedic Associates of Dutchess County, has announced the protected health information of certain patients was potentially stolen in a recent cyberattack.

The security incident was detected on March 5, 2021 when suspicious activity was identified in its systems. An investigation into the incident confirmed its systems had been accessed by unauthorized individuals on or around March 1, 2021. The attackers gained access to certain systems and encrypted files and issued a ransom demand for the keys to unlock the encrypted files.

The attackers claimed they had stolen sensitive data prior to the encryption of files, although it was not possible to determine which files had been stolen. A review of the systems accessed by the attackers revealed they contained files that included protected health information such as names, addresses, contact telephone numbers, email addresses, emergency contact information, diagnoses, treatment information, medical record numbers, health insurance information, payment details, dates of birth, and Social Security numbers.

Individuals potentially affected by the breach have been notified by mail and have been offered a 12- month complimentary membership to credit monitoring and identity theft protection services. To date, there have been no reports of attempted or actual misuse of any patient data.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The protected health information of 331,376 individuals was potentially compromised in the attack.

PHI of 5,426 Individuals Compromised in Entrust Medical Billing Ransomware Attack

Entrust Medical Billing, a Canton, OH-based medical billing company, has suffered a ransomware attack in which the protected health information of 5,426 individuals may have been compromised.

Third-party cybersecurity professionals were engaged to assist with the investigation and determine the extent of the breach. On or around March 1, 2021, the investigation confirmed some of the files exfiltrated by the attackers contained protected health information such as names, addresses, dates of birth, medical diagnosis/clinical information/treatment type or location, medical procedure information, patient account number, and health insurance information.

While data theft was confirmed, no evidence has been found to indicate actual or attempted misuse of any of the stolen data. Affected individuals have now been notified and those whose Social Security number has been compromised have been offered complimentary credit monitoring services. New technical safeguards have now been implemented and monitoring across its network environment has been increased.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist