Maryland Medical Center/Dr. Morrill
Disclosed Dec 28, 20169 years ago10,000 affectedConfirmed
On November 3, 2016, a cyber-attacker accessed the covered entity’s (CE) practice computer system to deny access to certain portions of its computer system until a ransom was paid. The CE, Maryland Medical Center, shut down the system and utilized its backup to recover the lost information. The compromised information consisted of correspondence to patients regarding test results utilizing patient names, date of birth, social security number. The documents targeted by the virus affected approximately 10,000 individuals. After the compromise, the CE put the computer system in safe mode, conducted a virus scan, and quarantined and destroyed computer viruses. The CE confirmed that it closed the system network and password protected the Wi-Fi. The CE implemented a procedure requiring pre-approval of all electronic devices connected to its systems and requiring a firewall for remote access to the virtual private network (VPN). The CE sanctioned the employee responsible for the breach and retrained all employees. OCR reviewed the CE’s current risk assessment and obtained assurances that the CE implemented the corrective actions listed.
What is known
| People affected | 10,000 (as reported to HHS) |
|---|---|
| Disclosed | Dec 28, 2016 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Maryland Medical Center/Dr. Morrill (Healthcare Provider, MD)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Dec 28, 2016 | 10,000 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.