Clinton County Board of Developmental Disabilities
bd_09ff05d14f26fb50 · schema v1 · pii pii-v1
Full breach record for Clinton County Board of Developmental Disabilities →Clinton County Board of Developmental Disabilities reported to HHS on 2017-05-05 a Hacking/IT Incident affecting 1243 individuals. Breached information located on Network Server. The entity discovered on March 16, 2017, that a person accessed its computer server and deployed ransomware, preventing employee access to patient clinical information, diagnoses, and treatment data. The entity notified HHS, affected individuals, media, and local authorities. Remediation included decommissioning the server, migrating to cloud, upgrading anti-virus, updating password policies, and workforce training.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 5, 2017
- Raw hash
- f5a59e340ce385e3d2617d248c0550d7841f5266ad6d8ca0aa82810306785089
Source filing
Reporting entity
- Name
- Clinton County Board of Developmental Disabilitiesnorm: clinton county board of developmental disabilities
- Industry
- Health Care Services
Victim entity
- Name
- Clinton County Board of Developmental Disabilitiesnorm: clinton county board of developmental disabilities
- Industry
- Healthcaresource default
Incident
- Discovered
- Mar 16, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,243
- Data types
- PHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified HHSOCR obtained documented assurances that the CE implemented the corrective actions noted above
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(50 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Mar 16, 2017→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.