Skip to content

Walnut Place

Disclosed May 12, 20179 years ago5,000 affectedConfirmed

Official notice

The covered entity (CE), Walnut Place, experienced two ransomware attacks on one of its servers containing electronic protected health information (ePHI). The ePHI on the server included patients' names, social security numbers, driver’s license numbers, dates of birth, addresses, telephone numbers, medical record numbers, payment information, insurance information, and clinical information for a combined total of approximately 6,500 individuals for both incidents. The CE reported the second attack as a separate breach. Upon discovering the breach, the CE contained and stopped the attack by removing infected files from the server. The CE provided breach notification to HHS, affected individuals, and the media. The CE improved administrative and technically safeguards and retrained staff on observing and reporting malicious software. OCR obtained assurances that the CE implemented corrective actions to enhance its security controls.

What is known

People affected5,000 (as reported to HHS)
DisclosedMay 12, 2017
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Walnut Place (Healthcare Provider, TX)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalMay 12, 20175,000
HHS archivetotalJul 5, 20175,000
History of this record
  • 2026-09-25 · disclosed: 2017-07-05 to 2017-05-12 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Walnut Place

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.