J&J MEDICAL SERVICE NETWORK
Disclosed Sep 25, 20188 years ago2,500 affectedConfirmed
J & J Medical Service Network, Inc., the business associate (BA), reported that it was the victim of a cyber-attack involving ransomware. This attack affected the electronic protected health information (ePHI) of 17,479 individuals and the ePHI involved included names, addresses, birthdates, Social Security numbers, and clinical information. The BA was able to recover the data and a third-party forensic analysis found no evidence to conclude that the attacker accessed or exfiltrated the data. The BA notified HHS, affected individuals, and the media. Following this breach incident, the BA implemented additional administrative, technical, and security safeguards and retrained its workforce members. OCR obtained assurances that the business associate implemented the aforementioned corrective actions. Further, the BA notified OCR that it had closed its business.
What is known
| People affected | 2,500 (as reported to HHS) |
|---|---|
| Disclosed | Sep 25, 2018 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): J&J MEDICAL SERVICE NETWORK (Business Associate, TX)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Sep 25, 2018 | 2,500 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.