Premier Medical Associates
Disclosed Sep 15, 20179 years ago876 affectedConfirmed
On August 8, 2017, the covered entity (CE), Premier Medical Associates, received four website submissions informing them that patients were getting suspicious “phishing” emails from the CE with an attachment requesting protected health information (PHI). The CE investigated the incident and discovered that the suspicious emails were coming from a personal g-mail account and determined that a website misconfiguration made by the webmaster on July 24, 2017, inadvertently permitted access to the public. The misconfiguration was corrected on August 9, 2017, and the CE terminated the contracted services with the webmaster. The CE added an email fraud alert to every page of its website, placed a fraud alert on its phone system, and sent messages to 24,000 patients through the patient portal informing patients of the fraudulent email. The CE created a list of anyone who made submissions to the website in order to determine what type of information had been accessed and who may have viewed the web pages from July 24, 2017, through August 8, 2017 and determined that the breach affected 875 individuals. The CE provided breach notification to HHS, affected individuals, and the media. The CE e
What is known
| People affected | 876 (as reported to HHS) |
|---|---|
| Disclosed | Sep 15, 2017 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Premier Medical Associates (Healthcare Provider, PA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Sep 15, 2017 | 876 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.