Metro Santurce
Disclosed Apr 13, 20197 years ago305,737 affectedConfirmed
The covered entities (CEs), Metro Santurce Inc. dba Hospital Pavia Santurce and Metro Hato Rey, Inc. dba Hospital Pavia Hato Rey, reported that both entities experienced a ransomware attack that affected the electronic protected health information (ePHI) of 305,737 individuals. The ePHI involved included names, addresses, dates of births, drivers’ license numbers, claims and financial information, diagnoses, lab results, medications prescribed, and other treatment information. The CEs notified HHS, affected individuals, and the media. In their mitigation efforts, the CEs strengthened their administrative and technical safeguards to better protect ePHI.
What is known
| People affected | 305,737 (as reported to HHS) |
|---|---|
| Disclosed | Apr 13, 2019 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Metro Santurce (Healthcare Provider, )ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Apr 13, 2019 | 305,737 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.