Northeast Philadelphia Vascular Surgeons
Disclosed Mar 27, 20197 years ago8,193 affectedConfirmed
Northeast Philadelphia Vascular Surgeons, the covered entity (CE), reported that on March 27, 2019, an unauthorized party gained access to the protected health information (PHI) stored on its server and deployed a ransomware attack that encrypted some files. A third party investigation found a remote desktop login with an IP address originating from Russia. The attack affected 8,193 individuals. After investigation, the evidence did not find any actual opening of the files or exposure of PHI. The CE implemented multi-factor authentication for any remote access into its online environment, a mandatory virtual private network, and location restrictions for remote access. Northeast Philadelphia Vascular Surgeons also provided notification of the breach to all affected individuals. During its investigation, OCR reviewed the newly implemented policies and procedures on uses and disclosures of PHI and the safeguarding of sensitive data. In addition, OCR provided technical guidance leading to the option of a risk analysis. The CE will conduct regular enterprise-wide risk assessments to address the risks and vulnerabilities identified in the risk analysis. OCR obtained assurances that the
What is known
| People affected | 8,193 (as reported by the organization) |
|---|---|
| Disclosed | Mar 27, 2019 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Maine Attorney General breach notice archive: Northeast Philadelphia Vascular Surgeonsmaine.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Northeast Philadelphia Vascular Surgeons (Healthcare Provider, PA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Maine AGresidents of ME | Mar 27, 2019 | 1 |
| HHS archivetotal | Mar 27, 2019 | 8,193 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: ["names"] to ["names","health"] · backfill source
- 2026-09-25 · summary: empty to Northeast Philadelphia Vascular Surgeons, the covered entity (CE), reported that on March 27, 2019, an unauthorized party gained access to the protected health information (PHI) stored on its server and deployed a ransomware attack that enc · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Maine AG), confirmed by Maine AG. Record counts are as reported. Not legal advice.