Estill County Chiropractic
Disclosed Mar 16, 20179 years ago5,335 affectedConfirmed
The covered entity (CE), Estill County Chiropractic, discovered that an unauthorized user installed malicious software (ransomware) on its computer system that encrypted 5,335 patients’ files. An investigation revealed that the hacker was able to gain access to the CE’s server using the administrative credentials of its electronic medical records vendor. The types of PHI involved in the incident included patients’ names, addresses, phone numbers, email addresses, dates of birth, social security numbers, provider notes, health plan and claims numbers, clinical information, and health diagnoses. The CE provided breach notification to HHS, affected individuals, and the media. The CE immediately disconnected its server and workstations, hired outside counsel, and consulted forensic investigators. Further, the CE purchased and installed a new server and installed a new version of its electronic medical record software with strengthened safeguards. OCR provided technical assistance to the CE regarding business associate (BA) agreements with vendors, and the CE provided OCR with an updated BA agreement. The CE also retrained its workforce and updated its HIPAA policies and procedures. OCR
What is known
| People affected | 5,335 (as reported to HHS) |
|---|---|
| Disclosed | Mar 16, 2017 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Estill County Chiropractic (Healthcare Provider, KY)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Mar 16, 2017 | 5,335 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.