Overlake Arthritis and Osteoporosis Center
Disclosed Jul 6, 20188 years ago627 affectedConfirmed
The covered entity (CE) reported that on May 11, 2018, a workforce member fell prey to a phishing attack causing her to call a fake Microsoft Support phone number and allow an unauthorized user to access her computer which contained protected health information (PHI). The computer contained the PHI of approximately 627 individuals’ demographic and clinical information. The CE provided breach notification to HHS, affected individuals, and the media and offered complimentary credit monitoring and a dedicated toll-free number to handle questions. The CE sanctioned the involved employee, implemented new technology to safeguard ePHI, and trained all workforce members on the issues raised in the breach. OCR provided substantial technical assistance to the CE and obtained assurances that the CE implemented the corrective actions noted above.
What is known
| People affected | 627 (as reported to HHS) |
|---|---|
| Disclosed | Jul 6, 2018 |
| Discovered | May 11, 2018 |
| Happened | May 11, 2018 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Washington Attorney General breach notice: Overlake Arthritis and Osteoporosis Centeratg.wa.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Overlake arthritis and Osteoporosis Center (Healthcare Provider, WA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jul 6, 2018 | 627 |
| Washington AGresidents of WA | Jul 12, 2018 | 627 |
History of this record
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 627 · backfill source
- 2026-09-25 · disclosed: 2018-07-12 to 2018-07-06 · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE) reported that on May 11, 2018, a workforce member fell prey to a phishing attack causing her to call a fake Microsoft Support phone number and allow an unauthorized user to access her computer which contained protect · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Washington AG), confirmed by Washington AG. Record counts are as reported. Not legal advice.