Lee Rice D.O., Medical
Disclosed Jul 15, 201610 years ago2,473 affectedConfirmed
Malware was installed by cyber-intruders into PrognoCIS, the medical records system of the business associate (BA), Bizmatics, Inc. The breach affected approximately 2,473 individuals who were patients of the covered entity (CE), Lee Rice D.O. Medical Corporation d/b/a Lifewellness Institute. The types of protected health information (PHI) involved included full names, addresses, dates of birth, phone numbers, sex, marital status, social security numbers, claims information, diagnoses/conditions, lab results, and medications. The CE provided breach notification to HHS, affected individuals, and the media and also provided substitute notice. In response to the breach, the BA notified and cooperated with the FBI in its investigation. In addition, the BA consulted with an independent cyber-security firm to assess the extent of the breach and to implement additional protective measures to prevent a similar breach from occurring in the future. OCR obtained assurances that the CE and BA implemented the corrective actions noted above.
What is known
| People affected | 2,473 (as reported to HHS) |
|---|---|
| Disclosed | Jul 15, 2016 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Lee Rice D.O., Medical (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jul 15, 2016 | 2,473 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.