Apple Valley Clinic
Disclosed Mar 26, 20215 years ago157,939 affectedConfirmed
The covered entity (CE), Apple Valley Clinic, reported that its business associate (BA) was the victim of a cyber-attack that compromised the protected health information (PHI) of 157,939 individuals. The PHI involved included names, addresses, dates of birth, drivers’ license numbers, Social Security numbers, claims and financial information, diagnoses, lab results, and medication information. The CE notified HHS, affected individuals, the media, and provided substitute notice on its website. In response to the breach, the CE offered complimentary credit monitoring services to affected individuals, implemented additional technical safeguards, and terminated its business relationship with the BA. OCR provided technical assistance to the CE with respect to the HIPAA Privacy Rule.
What is known
| People affected | 157,939 (as reported to HHS) |
|---|---|
| Disclosed | Mar 26, 2021 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Apple Valley Clinic (Healthcare Provider, MN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Mar 26, 2021 | 157,939 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.