Desert Care Family and Sports Medicine
Disclosed Dec 20, 20169 years ago500 affectedConfirmed
In early August of 2016, ransomware infected Desert Care Family and Sports Medicine’s (DCFSM’s) server and encrypted all of the data contained on the server. DCFSM contacted its IT provider and Data Doctors but was unable to break one of the two encryption variants. DCFSM was also unable to recover the patient data on the server. DCFSM contacted the Casa Grande Police Department and the FBI to notify them of this incident. DCFSM is unsure how many individuals were affected by this incident but reported the breach as affecting over 500 individuals in an abundance of caution. DCFSM provided substitute and media breach notification but did not provide individual breach notification because its server was inaccessible due to the ransomware attack and it could not retrieve its patients’ contact information. In response to the breach, DCFSM added an off-site backup, retrained all of its employees, and obtained a new server. DCFSM closed its business on December 20, 2016 and as of January 1, 2017, another business is operating the practice. OCR provided DCFSM with technical assistance regarding the Security Rule risk analysis and risk management provisions.
What is known
| People affected | 500 (as reported to HHS) |
|---|---|
| Disclosed | Dec 20, 2016 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Desert Care Family and Sports Medicine (Healthcare Provider, AZ)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Dec 20, 2016 | 500 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.