Skip to content

East Valley Community Health Center

Disclosed Dec 6, 20169 years ago65,000 affectedConfirmed

Official notice

On October 18, 2016, an unknown individual logged into one of the covered entity's (CE) computer servers without authorization and installed Troldesh/Shade malware, encrypting files that were stored on the server. Upon initial review, it appeared that no protected health information (PHI) was contained in the files; however, after further review the CE determined that one of the files contained claims data for 65,000 patients it had transmitted to its clearinghouse. The PHI involved in the breach included patients’ names, dates of birth, addresses, medical record numbers, health diagnosis codes and insurance account numbers. The CE provided breach notification to HHS, affected individuals, and the media. In response to OCR’s investigation, the CE revised its Security Rule policies and procedures

What is known

People affected65,000 (as reported to HHS)
DisclosedDec 6, 2016
HappenedOct 18, 2016
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
California AGresidents of CADec 6, 2016
HHS archivetotalDec 15, 201665,000
History of this record
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 65000 · backfill source
  • 2026-09-25 · summary: empty to On October 18, 2016, an unknown individual logged into one of the covered entity's (CE) computer servers without authorization and installed Troldesh/Shade malware, encrypting files that were stored on the server. Upon initial review, it ap · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about East Valley Community Health Center

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.