Urgent Care Clinic of Oxford
Disclosed Sep 30, 20169 years ago64,000 affectedConfirmed
On August 2, 2016, the covered entity (CE), Urgent Care Clinic of Oxford, discovered that its server was hacked by an unauthorized third party. The CE investigated and determined that the hackers gained access to the server through an administrative account set up by the CE’s technology contractor. The types of protected health information (PHI) involved in the breach included patient names, addresses, dates of birth, driver’s licenses, social security numbers, claims information, diagnoses and conditions, lab results, and medications, affecting approximately 64,000 individuals. The CE provided breach notification to HHS, affected individuals, and the media. In response to the breach, the CE immediately shut down its server’s remote access, contacted law enforcement, hired forensic investigators and installed a new network sonic wall to protect its entire system. OCR provided technical assistance to the CE regarding risk analysis and risk management. Consequently, the CE altered its policies and procedures to include full monthly testing of its server and a new risk assessment in accordance with OCR’s Security Risk Assessment Tool. Moreover, the CE retrained its workforce on its up
What is known
| People affected | 64,000 (as reported to HHS) |
|---|---|
| Disclosed | Sep 30, 2016 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Urgent Care Clinic of Oxford (Healthcare Provider, MS)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Sep 30, 2016 | 64,000 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.