Skip to content

Harrisburg Gastroenterology

Disclosed Apr 28, 20179 years ago93,323 affectedConfirmed

Official notice

Harrisburg Gastroenterology LTD., the covered entity (CE) reported that as a result of a ransomware attack, and subsequent investigation, the CE discovered that an unauthorized party had obtained the credentials allowing access to the CE’s record systems The breach affected 93,323 individuals and the types of protected health information (PHI) included demographic and clinical information, health insurance information, and social security numbers. With the assistance of a forensic business associate (BA), the CE deactivated the compromised domain account and reset all account passwords. The forensic information technology (IT) consulting firm conducted a comprehensive assessment to identify risks and vulnerabilities and to provide assistance with the implementation of new technical safeguards. The CE contracted with a new IT consulting firm, replaced its existing computer network firewall with one providing enhanced monitoring and intrusion detection/prevention capabilities and created an additional layer of computer server security. The CE also reviewed all user accounts and limited permissions on certain accounts to restrict standard users from making unapproved changes or instal

What is known

People affected93,323 (as reported to HHS)
DisclosedApr 28, 2017
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalApr 28, 201793,323
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Harrisburg Gastroenterology

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.