Longs Peak Family Practice
Disclosed Dec 27, 20178 years ago16,238 affectedConfirmed
On November 5, 2017, Longs Peak Family Practice, the covered entity (CE), discovered that a hacker had penetrated its computer network and executed malicious code within the network before the CE could prevent it. Though the malicious code included ransomware that encrypted certain files, the CE used backup files to rebuild and restore its network without paying any ransom. The CE hired a company to perform a forensic investigation, which revealed evidence of unauthorized access to some parts of its computer system on November 5, 9, and 10, 2017, resulting in the breach of 16,238 individuals’ electronic protected health information (PHI). The types of PHI involved included demographic, financial, and clinical information. The CE provided breach notification to affected individuals, the media, and HHS. The CE also mitigated the effects of the breach by providing affected individuals with credit monitoring information and contact information should they have questions regarding the breach. Following the breach, the CE improved technical safeguards by verifying that non-essential router ports were closed, wiping and restoring affected hard drives, scanning computing devices for viruse
What is known
| People affected | 16,238 (as reported to HHS) |
|---|---|
| Disclosed | Dec 27, 2017 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Longs Peak Family Practice (Healthcare Provider, CO)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Dec 27, 2017 | 16,238 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.