Institute for Women's Health
Disclosed Aug 18, 20179 years ago15,761 affectedConfirmed
Institute for Women’s Health, the covered entity (CE), reported that a keylogger virus on its computer network captured information keyed into the CE’s system for more than a month. The protected health information (PHI) of 15,761 individuals was involved in the breach. The types of PHI included demographic, financial, and clinical information. The CE notified the affected individuals and the media. During the investigation, OCR provided technical assistance concerning a risk analysis which the CE subsequently provided. Based on further technical assistance from OCR, the CE updated and implemented technical and procedural changes to prevent a similar event from occurring in the future and retrained its staff.
What is known
| People affected | 15,761 (as reported to HHS) |
|---|---|
| Disclosed | Aug 18, 2017 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Institute for Women's Health (Healthcare Provider, TX)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Aug 18, 2017 | 15,761 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.