Andrea Yaley, DDS
Disclosed Jul 10, 20179 years ago1,200 affectedConfirmed
The covered entity (CE), Andrea Yaley, DDS, received a ransomware notice that encrypted its computers. The types of protected health information (PHI) involved in the incident included the full names, addresses, dates of birth, social security numbers, claims information, billing codes, and clinical information of approximately 1,200 individuals. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE immediately reported the incident to local and federal law enforcement and restored patient files from backups. As a result of this incident, the CE implemented policies and procedures, upgraded its computer equipment and software, and contracted with a company to provide active monitoring of computer activity in order to safeguard electronic PHI. OCR obtained assurances that the CE implemented the corrective actions listed.
What is known
| People affected | 1,200 (as reported to HHS) |
|---|---|
| Disclosed | Jul 10, 2017 |
| Happened | May 19, 2017 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Andrea Yaley, DDSoag.ca.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Andrea Yaley, DDS (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| California AGresidents of CA | Jul 10, 2017 | |
| HHS archivetotal | Jul 10, 2017 | 1,200 |
History of this record
- 2026-09-25 · sector: other to health · backfill source
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 1200 · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), Andrea Yaley, DDS, received a ransomware notice that encrypted its computers. The types of protected health information (PHI) involved in the incident included the full names, addresses, dates of birth, social secur · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.