Plastic Surgery Associates of South Dakota
Disclosed Jul 27, 20179 years ago10,229 affectedConfirmed
Today, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), announced a settlement with Plastic Surgery Associates of South Dakota in Sioux Falls, for several potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule, following its investigation into a ransomware attack breach by OCR. Ransomware and hacking are the primary cyber-threats in health care. Ransomware is a type of malware (malicious software) designed to deny access to a user’s data, usually by encrypting the data with a key known only to the hacker who deployed the malware, until a ransom is paid. There has been a 264% increase in large breaches reported to OCR involving ransomware attacks since 2018. October is Cybersecurity Awareness Month, and OCR has been working with health plans, health care clearinghouses, most health care providers and their business associates to raise awareness of the types of cyberattacks occurring and how to improve data security. “Ransomware attacks often reveal a provider’s underlying failures to comply with the HIPAA Security Rule requirements such as conducting a risk analysis or managing identified ri
What is known
| People affected | 10,229 (as reported to HHS) |
|---|---|
| Disclosed | Jul 27, 2017 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Plastic Surgery Associates of South Dakota (Healthcare Provider, SD)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jul 27, 2017 | 10,229 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.