Vascular Surgical Associates
Disclosed Nov 10, 20169 years ago36,496 affectedConfirmed
The covered entity (CE), Vascular Surgical Associates, discovered that on September 13, 2016, it had experienced a distributed denial of services attack. Upon investigation, it was determined that unauthorized third parties were able to gain access into the CE’s computer server through an administrative account set up by its electronic health records (EHR) system vendor and to enter the server and obtain PHI undetected after installing software to prevent the CE from seeing the activity. The types of PHI on the CE’s server included patients' names, addresses, dates of birth, and health diagnoses and conditions. The server contained PHI for approximately 36,496 individuals. The CE provided breach notification to HHS, affected individuals, and the media. In response to the breach, the CE immediately terminated the unauthorized third parties’ access to its server, changed and strengthened passwords and contacted law enforcement. Additionally, the CE strengthened the security of its server by implementing Sonicwall protection, antivirus software, and Secure Sockets Layer virtual private network, and conducting daily log reviews looking for anomalies. Furthermore, the CE rebuilt its net
What is known
| People affected | 36,496 (as reported to HHS) |
|---|---|
| Disclosed | Nov 10, 2016 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Vascular Surgical Associates (Healthcare Provider, GA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Nov 10, 2016 | 36,496 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.