NMMalwareHealthcareHealthcareRansomwareBusiness Associate (HIPAA)Customer Data InvolvedData ExfiltratedData EncryptedRansom DemandedPHIHEALTH_BASICIDENTITY_BASICLowContained
Artesia General Hospital
bd_14e9656496895ff9 · schema v1 · pii pii-v1
Full breach record for Artesia General Hospital →Artesia General Hospital reported to HHS on 2018-02-27 a Hacking/IT Incident affecting 864 individuals. Breached information located on Network Server. The breach was caused by business associate Nuance Communications/Fast Health when their server was taken offline by ransomware between Nov 20, 2017 and Dec 9, 2017. Patient names, DOBs, and treatment info were exposed.
HIPAA clockDiscovered Dec 9, 2017 → Notified Feb 27, 201880d ✗ HIPAA 60-day late11 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed864 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Feb 27, 2018
- Raw hash
- 54a2a31af41919c58e3c98a137d4f0fec560a36ac0db8cb968997c462bd14d70
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Artesia General Hospitalnorm: artesia general hospital
- Industry
- Health Care Services
Victim entity
- Name
- Artesia General Hospitalnorm: artesia general hospital
- Industry
- Healthcaresource default
Incident
- Discovered
- Dec 9, 2017
- Materiality determined
- —
- Notification sent
- Feb 27, 2018
- Affected individuals
- 864
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- OCR opened an investigation of the CE to determine compliance with the Privacy Rule’s BA contract requirementsOCR determined that the BAA appears to comply with the requirements specified in the Privacy RuleOCR opened a separate review of the BA
- Third party
- via Nuance Communications/Fast Healthbusiness associate
Compliance
- Time to disclose
- 11 weeks(80 days from discovery to filing)
- Compliance flags
- HIPAA 60-day late · 80dHHS notified · 80d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Dec 9, 2017→ Notified: Feb 27, 201880d 60 days HIPAA 60-day late HIPAA Discovered: Dec 9, 2017→ Notified: Feb 27, 201880d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.