Skip to content

Vascular Surgical Associates

Disclosed Nov 10, 20169 years ago36,496 affectedConfirmed

Official notice

The covered entity (CE), Vascular Surgical Associates, discovered that on September 13, 2016, it had experienced a distributed denial of services attack. Upon investigation, it was determined that unauthorized third parties were able to gain access into the CE’s computer server through an administrative account set up by its electronic health records (EHR) system vendor and to enter the server and obtain PHI undetected after installing software to prevent the CE from seeing the activity. The types of PHI on the CE’s server included patients' names, addresses, dates of birth, and health diagnoses and conditions. The server contained PHI for approximately 36,496 individuals. The CE provided breach notification to HHS, affected individuals, and the media. In response to the breach, the CE immediately terminated the unauthorized third parties’ access to its server, changed and strengthened passwords and contacted law enforcement. Additionally, the CE strengthened the security of its server by implementing Sonicwall protection, antivirus software, and Secure Sockets Layer virtual private network, and conducting daily log reviews looking for anomalies. Furthermore, the CE rebuilt its net

What is known

People affected36,496 (as reported to HHS)
DisclosedNov 10, 2016
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalNov 10, 201636,496
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Vascular Surgical Associates

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.