The covered entity (CE), JDC Healthcare Management, reported that it was the victim of a ransomware attack affecting the protected health information (PHI) of 1,077,635 individuals. The PHI involved included names, dates of birth, addresses, Social Security and drivers’ license numbers, claims information, diagnoses, lab results, and medications. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE implemented additional technical safeguards, and trained its employees on the HIPAA Privacy Rule. OCR provided the CE with technical assistance regarding the requirements under the HIPAA Security Rule.
2026-09-25 · attack: unknown to hacking · backfill source
2026-09-25 · data_types: [] to ["names","health"] · backfill source
2026-09-25 · records_basis: empty to hhs · backfill source
2026-09-25 · records: empty to 1077635 · backfill source
2026-09-25 · disclosed: 2022-02-25 to 2021-10-07 · backfill source
2026-09-25 · summary: empty to The covered entity (CE), JDC Healthcare Management, reported that it was the victim of a ransomware attack affecting the protected health information (PHI) of 1,077,635 individuals. The PHI involved included names, dates of birth, addresses · backfill source
2026-09-25 · disclosed: 2022-05-19 to 2022-02-25 · backfill source