Jemison Internal Medicine
Disclosed Feb 16, 20188 years ago6,550 affectedConfirmed
On December 20, 2017, Jemison Internal Medicine, P.C., the covered entity (CE), discovered that files in its electronic medical records (EMR) were encrypted by ransomware. Through its contracted forensic investigator, Altep, the CE found that there was unauthorized access through its remote desktop protocol (RDP) service and that the protected health information (PHI) for 6,550 individuals was exposed. The exposed PHI included names, addresses, birthdates, driver’s license information, social security numbers, insurance information, and medical information. In response to the breach, the CE reset all system passwords, implemented multifactor authentication for all remote access, and reviewed its HIPAA policies and procedures. As a result of this review and OCR’s technical assistance, the CE implemented new policies and procedures regarding its security and risk management program. The CE provided breach notification to HHS, the affected individuals, and the media, and posted substitute notice on its website. OCR obtained assurances that the CE implemented the corrective actions noted above.
What is known
| People affected | 6,550 (as reported to HHS) |
|---|---|
| Disclosed | Feb 16, 2018 |
| Happened | Dec 20, 2017 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2018 data breach report: Jemison Internal Medicinein.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Jemison Internal Medicine (Health Plan, AL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Feb 16, 2018 | 3 |
| HHS archivetotal | Feb 16, 2018 | 6,550 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: organization to hhs · backfill source
- 2026-09-25 · records: 6229 to 6550 · backfill source
- 2026-09-25 · summary: empty to On December 20, 2017, Jemison Internal Medicine, P.C., the covered entity (CE), discovered that files in its electronic medical records (EMR) were encrypted by ransomware. Through its contracted forensic investigator, Altep, the CE found th · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.