The covered entity (CE), You and Your Health family Care, Inc., discovered a ransomware virus accessed its server through an open firewall embrasure on September 11, 2016. The ransomware accessed data that included patient names, addresses, dates of birth, Social surety numbers, and clinical information for 1,456 individuals. The ce provided nag notification to HHS, affected individuals, and the media. In response to the hack, the ce initiated a comprehensive critique of its privacy and security safeguards, secured all open ports in its firewall, reviewed and secured all user accounts and strengthened passwords, and installed additional security software. It developed a program to implement an audit system and encryption mechanisms, and retrain all staff after it finishes the in-depth refresh and update of its concealment and security policies. Additionally, it will conduct a risk analysis on an annual basis moving forward. OCR obtained assurances that the CE implemented the corrective actions listed above. location of hacked information: Network Server Business colligate present: no