Primary Care Specialists
Disclosed Mar 9, 20179 years ago65,000 affectedConfirmed
On February 27, 2017, the covered entity (CE), Primary Care Specialists, Inc., experienced a cyber-attack in which an unauthorized user accessed the CE’s system by hacking a user account that had been granted administrative privileges. The CE initially reported that approximately 65,000 individuals were affected and the protected health information (PHI) involved included names, addresses, dates of birth, drivers’ license numbers, social security numbers, claims information, diagnoses, lab results, and medications. However, after completing its investigation into the incident, which included a forensic analysis and the assistance of a third party IT service partner, the CE concluded that there was a low probability of compromise to any PHI. The CE provided OCR with documentation of its investigation and conclusion. To prevent a similar type of attack in the future, the CE reset all passwords, implemented new password requirements, reviewed and restructured domain administrator groups, disabled all external remote desktop access, retired the computer server from which the attacker gained access to the CE’s system and deployed additional malware protections. The CE also instituted qu
What is known
| People affected | 65,000 (as reported to HHS) |
|---|---|
| Disclosed | Mar 9, 2017 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Primary Care Specialists (Healthcare Provider, TN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Mar 9, 2017 | 65,000 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.