Skip to content

Grayling Anesthesia Associates

Disclosed Sep 23, 20224 years ago15,328 affectedConfirmed

Official notice

The covered entity (CE), Grayling Anesthesia Associates, reported that its business associate (BA) was the subject of a ransomware attack that affected the protected health information (PHI) of 15,328 individuals. The PHI involved included names, addresses, dates of birth, drivers’ license and Social Security numbers, claims and financial information, diagnoses, medications, and other treatment information. The CE notified HHS, the affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and the CE and BA implemented additional administrative, technical, and security safeguards to better protect PHI.

What is known

People affected15,328 (as reported to HHS)
DisclosedSep 23, 2022
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalSep 23, 202215,328
Vermont AGresidents of VTOct 24, 2022
History of this record
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 15328 · backfill source
  • 2026-09-25 · disclosed: 2022-10-24 to 2022-09-23 · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), Grayling Anesthesia Associates, reported that its business associate (BA) was the subject of a ransomware attack that affected the protected health information (PHI) of 15,328 individuals. The PHI involved included · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Vermont AG), confirmed by Vermont AG. Record counts are as reported. Not legal advice.

Everything about Grayling Anesthesia Associates

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.