Skip to content

Southwest Washington Regional Surgery Center

Disclosed Nov 6, 20187 years ago2,393 affectedConfirmed

Official notice

The covered entity (CE) reported to OCR that it was the victim of a malware/phishing attack, affecting the protected health information (PHI) of 2,393 individuals. The types of PHI involved in the breach included names, driver’s license information, social security numbers, claims information, credit card information and clinical information. The CE provided breach notification to HHS, affected individuals, and the media. OCR obtained evidence of the CE’s risk analysis and safeguards implemented prior to the breach. Following the breach, the CE strengthened its administrative and technical safeguards, including implementing multi-factor authentication for its email account.

What is known

People affected2,393 (as reported to HHS)
DisclosedNov 6, 2018
DiscoveredSep 25, 2018
HappenedMay 27, 2018
AttackPhishing
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
Washington AGresidents of WANov 6, 20181,690
Oregon DOJresidents of ORNov 6, 20182,393
HHS archivetotalNov 6, 20182,393
History of this record
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 2393 · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE) reported to OCR that it was the victim of a malware/phishing attack, affecting the protected health information (PHI) of 2,393 individuals. The types of PHI involved in the breach included names, driver’s license inf · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Washington AG), confirmed by Washington AG. Record counts are as reported. Not legal advice.

Everything about Southwest Washington Regional Surgery Center

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.