Maryland Medical Center/Dr. Morrill
bd_16da7c3f2f823dbd · schema v1 · pii pii-v1
Full breach record for Maryland Medical Center/Dr. Morrill →On November 3, 2016, a cyber-attacker accessed Maryland Medical Center/Dr. Morrill's (MD) practice desktop computer system and deployed ransomware, denying access until a ransom was paid. Approximately 10,000 individuals were affected. Compromised data included patient names, dates of birth, and Social Security numbers contained in test-result correspondence. The CE recovered via backup, quarantined viruses, implemented network controls and device pre-approval procedures, and sanctioned the responsible employee. HHS OCR verified corrective actions. Submitted to HHS on 2016-12-28.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Dec 28, 2016
- Raw hash
- e01542c36e3c004a1993c4705a0b46db037294d2570c055230a8b9fac7af18be
Source filing
Reporting entity
- Name
- Maryland Medical Center/Dr. Morrillnorm: maryland medical center dr morrill
- Industry
- Health Care Services
Victim entity
- Name
- Maryland Medical Center/Dr. Morrillnorm: maryland medical center dr morrill
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Nov 3, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 10,000
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- HHS OCR reviewed current risk assessment and obtained assurances that corrective actions were implemented.
Compliance
- Time to disclose
- 8 weeks(55 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Nov 3, 2016→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.