Skip to content

Maryland Medical Center/Dr. Morrill

Disclosed Dec 28, 20169 years ago10,000 affectedConfirmed

Official notice

On November 3, 2016, a cyber-attacker accessed the covered entity’s (CE) practice computer system to deny access to certain portions of its computer system until a ransom was paid. The CE, Maryland Medical Center, shut down the system and utilized its backup to recover the lost information. The compromised information consisted of correspondence to patients regarding test results utilizing patient names, date of birth, social security number. The documents targeted by the virus affected approximately 10,000 individuals. After the compromise, the CE put the computer system in safe mode, conducted a virus scan, and quarantined and destroyed computer viruses. The CE confirmed that it closed the system network and password protected the Wi-Fi. The CE implemented a procedure requiring pre-approval of all electronic devices connected to its systems and requiring a firewall for remote access to the virtual private network (VPN). The CE sanctioned the employee responsible for the breach and retrained all employees. OCR reviewed the CE’s current risk assessment and obtained assurances that the CE implemented the corrective actions listed.

What is known

People affected10,000 (as reported to HHS)
DisclosedDec 28, 2016
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalDec 28, 201610,000
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Maryland Medical Center/Dr. Morrill

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.