Skip to content

Longs Peak Family Practice

Disclosed Dec 27, 20178 years ago16,238 affectedConfirmed

Official notice

On November 5, 2017, Longs Peak Family Practice, the covered entity (CE), discovered that a hacker had penetrated its computer network and executed malicious code within the network before the CE could prevent it. Though the malicious code included ransomware that encrypted certain files, the CE used backup files to rebuild and restore its network without paying any ransom. The CE hired a company to perform a forensic investigation, which revealed evidence of unauthorized access to some parts of its computer system on November 5, 9, and 10, 2017, resulting in the breach of 16,238 individuals’ electronic protected health information (PHI). The types of PHI involved included demographic, financial, and clinical information. The CE provided breach notification to affected individuals, the media, and HHS. The CE also mitigated the effects of the breach by providing affected individuals with credit monitoring information and contact information should they have questions regarding the breach. Following the breach, the CE improved technical safeguards by verifying that non-essential router ports were closed, wiping and restoring affected hard drives, scanning computing devices for viruse

What is known

People affected16,238 (as reported to HHS)
DisclosedDec 27, 2017
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalDec 27, 201716,238
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Longs Peak Family Practice

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.