Hackensack Sleep and Pulmonary Center
Disclosed Nov 28, 20178 years ago16,474 affectedConfirmed
A ransomware virus infected the Hackensack Sleep and Pulmonary Center’s computer system that encrypted their electronic medical record files. The attacker demanded a ransom be paid in bitcoins to “unlock” the files. The covered entity (CE) did not pay the ransom and restored its medical records files by using an unaffected off-line backup copy. The electronic protected health information (ePHI) included 16,474 patients’ names, addresses, zip codes, dates of birth, drivers’ license numbers, social security numbers, gender, age, email addresses, lab results, medications, diagnoses and health insurance information. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE notified the New Jersey Cyber Unit, adopted encryption technologies, and strengthened password requirements. OCR obtained assurances that the CE implemented the corrective actions listed. The CE is expected to review its risk analysis to ensure it completely and appropriately identifies and assesses specific risks and vulnerabilities, develop and implement a risk management plan that addresses the process for managing and reducing the risks identified in the risk an
What is known
| People affected | 16,474 (as reported to HHS) |
|---|---|
| Disclosed | Nov 28, 2017 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Hackensack Sleep and Pulmonary Center (Healthcare Provider, NJ)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Nov 28, 2017 | 16,474 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.