Harrisburg Endoscopy and Surgery Center
Disclosed Apr 28, 20179 years ago9,092 affectedConfirmed
Harrisburg Endoscopy and Surgery Center, the covered entity (CE), filed a separate breach report that was also filed for Harrisburg Gastroenterology LTD concerning the same ransomware and subsequent investigation. The CE discovered that an unauthorized party obtained credentials allowing access to the CE’s record systems. The breach affected the protected health information (PHI) of 9,092 individuals for this CE, a subset of 93,323 for both CEs. The types of PHI involved included demographic and clinical information, health insurance numbers and social security numbers. With the assistance of a forensic business associate (BA), the CE deactivated the compromised domain account and reset all account passwords. The CE retained a forensic information technology (IT) consulting firm which conducted a comprehensive assessment to identify risks and vulnerabilities and to provide assistance with the implementation of new technical safeguards. The CE contracted with a new IT consulting firm, replaced its existing computer network firewall with one that has enhanced monitoring and intrusion detection/prevention capabilities and created an additional layer of computer server security. The CE
What is known
| People affected | 9,092 (as reported to HHS) |
|---|---|
| Disclosed | Apr 28, 2017 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Harrisburg Endoscopy and Surgery Center (Healthcare Provider, PA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Apr 28, 2017 | 9,092 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.