San Juan Oncology Associates
Disclosed Sep 29, 20169 years ago500 affectedConfirmed
On September 29, 2016, San Juan Oncology Associates, the covered entity (CE), reported that it discovered the “Guardware@india” virus on its server. The breach affected the electronic protected health information (ePHI) of 11,383 individuals. The types of ePHI involved in the breach included demographic, financial and, clinical information. Following the breach, the CE installed a new computer server and antivirus software, completed a post risk analysis, and revised its breach notice policy to include all the elements of the media notice requirements. OCR obtained documentation of the CE’s implementation of security controls that will be continuously updated to demonstrate a culture of security compliance. OCR also provided technical assistance on breach notification and security risk analysis requirements.
What is known
| People affected | 500 (as reported to HHS) |
|---|---|
| Disclosed | Sep 29, 2016 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): San Juan Oncology Associates (Healthcare Provider, NM)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Sep 29, 2016 | 500 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.