MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedRansom DemandedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICCREDENTIALSMediumContained
Dental Office of Dr. Douglas Boucher, DDS and Dr. Andrea Yaley, DDS
bd_06912879bc025a1e · schema v1 · pii pii-v1
Full breach record for Dental Office of Dr. Douglas Boucher, DDS and Dr. Andrea Yaley, DDS →Dental Office of Dr. Douglas Boucher, DDS and Dr. Andrea Yaley, DDS reported a ransomware attack occurring on or about May 19, 2017, with notification received on June 2, 2017. The attacker accessed the email system and potentially patient dental health records, exposing names, addresses, dates of birth, Social Security Numbers, and dental diagnoses. The office shut down systems, engaged security experts, and restored records from backups. Affected patients were offered 12 months of credit monitoring.
California clockDiscovered Jun 2, 2017 → Notified Jul 10, 201738d ✓ CA 60-day OK5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-100184
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 10, 2017
- Raw hash
- edcd674c80b742ecd81209d218bdcb1dd27540cfa59e43e4133c0e2003c357da
Reporting entity
- Name
- Dental Office of Dr. Douglas Boucher, DDS and Dr. Andrea Yaley, DDSnorm: dental office of dr douglas boucher dds and dr andrea yaley dds
- Domain
- douglasboucherdds.com
Victim entity
- Name
- Dental Office of Dr. Douglas Boucher, DDS and Dr. Andrea Yaley, DDSnorm: dental office of dr douglas boucher dds and dr andrea yaley dds
- Domain
- douglasboucherdds.com
Incident
- Discovered
- Jun 2, 2017
- Materiality determined
- —
- Notification sent
- Jul 10, 2017
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICCREDENTIALS
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1114 Email CollectionT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 5 weeks(38 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 38d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 2, 2017→ Notified: Jul 10, 201738d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.