Family Service Rochester
Disclosed Feb 17, 20179 years ago17,037 affectedConfirmed
On January 26, 2017, the covered entity (CE), Family Service Rochester, discovered that an unauthorized user had accessed its computer server, which contained the names, addresses, dates of birth, and social security numbers of approximately 17,037 patients. On the day the CE discovered the breach, it terminated all access to both its remote desktop and the compromised “programs” account. The CE also reviewed all accounts with access to the computer drive to ensure compliance with its password policy. The CE ensured that all accounts that had not been used in the past 90 days were disabled. The CE provided breach notification to HHS, affected individuals, and the media. As part of its risk analysis and risk management process, the CE also reviewed and revised its HIPAA policies and procedures. OCR obtained documented assurances that the CE implemented the corrective actions listed above.
What is known
| People affected | 17,037 (as reported to HHS) |
|---|---|
| Disclosed | Feb 17, 2017 |
| Happened | Dec 26, 2016 |
| Attack | Hacking |
| Data exposed | Names, Phone numbers, Addresses, Names |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Maine Attorney General breach notice archive: Family Service Rochestermaine.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Family Service Rochester (Healthcare Provider, MN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Maine AGresidents of ME | Feb 17, 2017 | 1 |
| HHS archivetotal | Feb 17, 2017 | 17,037 |
History of this record
- 2026-09-25 · sector: other to health · backfill source
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 17037 · backfill source
- 2026-09-25 · summary: empty to On January 26, 2017, the covered entity (CE), Family Service Rochester, discovered that an unauthorized user had accessed its computer server, which contained the names, addresses, dates of birth, and social security numbers of approximatel · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Maine AG), confirmed by Maine AG. Record counts are as reported. Not legal advice.