New Jersey Spine Center
Disclosed Sep 21, 201610 years ago28,308 affectedConfirmed
The covered entity’s (CE) computer system was attacked by a ransomware virus that encrypted files, including the electronic protected health information (ePHI) of approximately 28,000 patients and damaged the network operating system rendering all of the CE's files unusable. The ePHI included demographic and clinical information. The CE provided breach notification to HHS, affected individuals, and the media and provided free credit monitoring to affected individuals. Following the breach, the CE deactivated the username and password that the hacker used to break into its system. The CE provided OCR with copies of its HIPAA policies and procedures and assurances that staff was trained on the HIPAA Privacy and Security Rules. OCR obtained assurances that the CE implemented the corrective actions listed. The CE is expected to conduct a risk analysis and implement a corresponding remediation plan, review its existing HIPAA policies and procedures, execute a new business associate agreement with its electronic health records vendor, and conduct an assessment on applications to determine how important each is to patient care or business needs, in order to prioritize for data backup, dis
What is known
| People affected | 28,308 (as reported by the organization) |
|---|---|
| Disclosed | Sep 21, 2016 |
| Discovered | Jul 27, 2016 |
| Happened | Jul 27, 2016 |
| Attack | Hacking |
| Data exposed | Names, Social Security numbers, Government IDs, Payment cards, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Oregon DOJ breach notice: New Jersey Spine Centerjustice.oregon.gov · Official notice | Official notice |
| Indiana Attorney General 2016 data breach report: New Jersey Spine Centerin.gov · Official notice | Official notice |
| Maine Attorney General breach notice archive: New Jersey Spine Centermaine.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): New Jersey Spine Center (Healthcare Provider, NJ)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Sep 21, 2016 | 2 |
| Maine AGresidents of ME | Sep 21, 2016 | 3 |
| Oregon DOJresidents of OR | Sep 22, 2016 | 28,000 |
| HHS archivetotal | Sep 22, 2016 | 28,000 |
History of this record
- 2026-09-25 · sector: other to health · backfill source
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: ["names","ssn","government-id","payment-card"] to ["names","ssn","government-id","payment-card","health"] · backfill source
- 2026-09-25 · summary: empty to The covered entity’s (CE) computer system was attacked by a ransomware virus that encrypted files, including the electronic protected health information (ePHI) of approximately 28,000 patients and damaged the network operating system render · backfill source
- 2026-09-25 · data_types: [] to ["names","ssn","government-id","payment-card"] · backfill source
- 2026-09-25 · records_basis: empty to organization · backfill source
- 2026-09-25 · records: empty to 28308 · backfill source
- 2026-09-25 · disclosed: 2016-09-22 to 2016-09-21 · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Oregon DOJ), confirmed by Oregon DOJ. Record counts are as reported. Not legal advice.