Sovereign Medical Group, LLC
bd_06eec9349d365a22 · schema v1 · pii pii-v1
Full breach record for Sovereign Medical Group, LLC →Sovereign Medical Group, LLC (NJ Healthcare Provider) reported to HHS on 2012-12-27 a Hacking/IT Incident (ransomware) affecting 27,800 individuals. Data files on the network server were corrupted and rendered inaccessible; the CE received a ransom note demanding payment to restore access. ePHI exposed included demographics, SSNs, driver's license numbers, insurance information, dates of service, claims, diagnoses, and procedure codes. The CE notified law enforcement (police, county prosecutor, FBI), offered credit monitoring, and remediated by closing server ports, deploying web filtering, and disabling wireless networks. OCR provided HIPAA Security Rule technical assistance.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Dec 27, 2012
- Raw hash
- 90dc51015e53fe792c51221e8a2ead5bbe2d8d26560fb2248e4a9354de8fb549
Source filing
Reporting entity
- Name
- Sovereign Medical Group, LLCnorm: sovereign medical
- Industry
- Health Care Services
Victim entity
- Name
- Sovereign Medical Group, LLCnorm: sovereign medical
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 27,800
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- OCR opened an investigation and provided technical assistance regarding the HIPAA Security Rule.CE filed reports with the local police department, county prosecutor's office, and the Federal Bureau of Investigation.
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.