East Valley Community Health Center
Disclosed Dec 6, 20169 years ago65,000 affectedConfirmed
On October 18, 2016, an unknown individual logged into one of the covered entity's (CE) computer servers without authorization and installed Troldesh/Shade malware, encrypting files that were stored on the server. Upon initial review, it appeared that no protected health information (PHI) was contained in the files; however, after further review the CE determined that one of the files contained claims data for 65,000 patients it had transmitted to its clearinghouse. The PHI involved in the breach included patients’ names, dates of birth, addresses, medical record numbers, health diagnosis codes and insurance account numbers. The CE provided breach notification to HHS, affected individuals, and the media. In response to OCR’s investigation, the CE revised its Security Rule policies and procedures
What is known
| People affected | 65,000 (as reported to HHS) |
|---|---|
| Disclosed | Dec 6, 2016 |
| Happened | Oct 18, 2016 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: East Valley Community Health Centeroag.ca.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): East Valley Community Health Center (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| California AGresidents of CA | Dec 6, 2016 | |
| HHS archivetotal | Dec 15, 2016 | 65,000 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 65000 · backfill source
- 2026-09-25 · summary: empty to On October 18, 2016, an unknown individual logged into one of the covered entity's (CE) computer servers without authorization and installed Troldesh/Shade malware, encrypting files that were stored on the server. Upon initial review, it ap · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.