Valley Family Medicine
Disclosed Nov 3, 20178 years ago8,450 affectedConfirmed
Two employees took home a listing of patients, and one employee used the list to generate postcards notifying patients of his new practice. The breach affected approximately 8,450 individuals. The protected health information (PHI) included names and addresses. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the covered entity (CE) updated its electronic health records and billing systems, and adopted encryption to prevent future similar breaches. As a result of OCR’s investigation and provision of technical assistance, the CE conducted a risk analysis.
What is known
| People affected | 8,450 (as reported to HHS) |
|---|---|
| Disclosed | Nov 3, 2017 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Valley Family Medicine (Healthcare Provider, VA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Nov 3, 2017 | 8,450 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.