Center for Facial Restoration
Disclosed Dec 26, 20196 years ago3,600 affectedConfirmed
The covered entity (CE), The Center for Facial Restoration, reported that it was the victim of a ransomware attack affecting the electronic protected health information (ePHI) of 3,600 individuals. The ePHI involved included names, addresses, dates of birth, driver’ license numbers, Social Security numbers, financial and claims information, diagnoses/conditions, and medications prescribed. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE implemented additional technical safeguards, drafted new policies and procedures, and retrained its workforce. OCR provided the CE with technical assistance regarding the HIPAA Breach Notification Rule.
What is known
| People affected | 3,600 (as reported to HHS) |
|---|---|
| Disclosed | Dec 26, 2019 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Center for Facial Restoration (Healthcare Provider, FL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Dec 26, 2019 | 3,600 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.