Skip to content

Steward Medical Group

Disclosed Nov 28, 20187 years ago16,276 affectedConfirmed

Official notice

A business associate (BA), Business and Professional Exchange, that provided the covered entity (CE) with 24-hour telephone answering services, experienced a ransomware incident affecting their computer network servers. The breach involved the electronic protected health information (ePHI) of approximately 16,276 individuals, including demographic and clinical information. The CE provided breach notification to HHS, affected individuals, and the media. OCR reviewed the BA agreement between the BA and CE and it appears to comply with the requirements of the HIPAA Rules. Following this incident, the parties no longer have a business relationship.

What is known

People affected16,276 (as reported to HHS)
DisclosedNov 28, 2018
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Steward Medical Group (Healthcare Provider, MA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalNov 28, 201816,276

Other breaches at Steward Medical Group

BreachAffected
Disclosed Jul 26, 2022Jul 26, 20224 years agoInsider2,188
Disclosed Jun 4, 2021Jun 4, 20215 years agoHacking640
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Steward Medical Group

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.