Skip to content

Green Ridge Behavioral Health

Disclosed Feb 11, 20197 years ago14,000 affectedConfirmed

Official notice

The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), announced a settlement under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) with Green Ridge Behavioral Health, LLC, a Maryland-based practice that provides psychiatric evaluations, medication management, and psychotherapy. OCR enforces the HIPAA Privacy, Security, and Breach Notification Rules, which sets forth the requirements that HIPAA covered entities (most health care providers, health plans, and health care clearinghouses) and their business associates must follow to protect the privacy and security of protected health information. The settlement resolves an investigation following a ransomware attack that affected the protected health information of more than 14,000 individuals. Ransomware is a type of malware (malicious software) designed to deny access to a user’s data, usually by encrypting the data with a key known only to the hacker who deployed the malware, until a ransom is paid. This marks the second settlement that OCR has reached with a HIPAA regulated entity for potential violations identified during an investigation following a ransomware attack. “Rans

What is known

People affected14,000 (as reported to HHS)
DisclosedFeb 11, 2019
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalFeb 11, 201914,000
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Green Ridge Behavioral Health

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.