ABCD Pediatrics
Disclosed Mar 26, 20179 years ago55,447 affectedConfirmed
ABCD Pediatrics, P.A., the covered entity (CE) reported that its electronic health records system was hacked and ransomware began encrypting protected health information (PHI) stored on its servers. The PHI included patient names, addresses, dates of birth, Social Security numbers, drivers’ license information, diagnoses, medical conditions, lab results, medications, other treatments, and claims information. Approximately 55,447 individuals were affected by the breach. The CE took several corrective action steps to resolve the issue raised in the breach report. The corrective action taken included closing down remote access to terminal services and requiring workforce members to use a Virtual Private Network for remote access. The CE also conducted audits and disabled inactive user accounts, strengthened password requirements, and implemented account lockout policies. During the investigation, OCR verified that the CE implemented encryption on laptops and mobile devices. OCR provided technical assistance concerning the breach notification policies of the CE and received revised versions of those policies. The CE also revised policies regarding periodic risk analyses to update its S
What is known
| People affected | 55,447 (as reported to HHS) |
|---|---|
| Disclosed | Mar 26, 2017 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): ABCD Pediatrics (Healthcare Provider, TX)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Mar 26, 2017 | 55,447 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.