COMalwareHealthcareHealthcareRansomwareCustomer Data InvolvedData EncryptedHEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNTMediumResolved
Allergy, Asthma & Immunology of the Rockies, PC
bd_15f1e0d73ac4af5a · schema v1 · pii pii-v1
Full breach record for Allergy, Asthma & Immunology of the Rockies, PC →On June 17, 2016, Allergy, Asthma & Immunology of the Rockies, PC (Colorado) discovered its network server had been hacked with evidence of ransomware and unknown accounts on the system. ePHI of up to 6,851 individuals—including demographic, financial, and clinical information—was compromised. The CE replaced the infected hard drive, rebuilt its system, and implemented a VPN. OCR's investigation led to revised ePHI safeguarding procedures, updated risk analysis, and risk management plan improvements.
HIPAA clockDiscovered Jun 17, 2016 → Notified Jun 17, 20160d ✓ HIPAA 60-day OK≤1 day discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed6,851 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jun 17, 2016
- Raw hash
- f5701c95b49618f7069d0bb65916ffcf6231bce88c14ffcfba659a3d24f9ae7f
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Allergy, Asthma & Immunology of the Rockies, PCnorm: allergy asthma immunology of the rockies
- Industry
- Health Care Services
Victim entity
- Name
- Allergy, Asthma & Immunology of the Rockies, PCnorm: allergy asthma immunology of the rockies
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Jun 17, 2016
- Materiality determined
- —
- Notification sent
- Jun 17, 2016
- Affected individuals
- 6,851
- Data types
- HEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- HHS OCR investigation; CE revised procedures for safeguarding ePHI and protecting against malicious software; CE updated risk analysis and risk management plan per OCR technical assistance on HIPAA Security Rule.
Compliance
- Time to disclose
- ≤1 day(0 days from discovery to filing)
- Compliance flags
- HIPAA 60-day OK · 0dHHS notified · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jun 17, 2016→ Notified: Jun 17, 20160d 60 days HIPAA 60-day OK HIPAA Discovered: Jun 17, 2016→ Notified: Jun 17, 20160d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.