Maryland Medical Center/Dr. Morrill
bd_16da7c3f2f823dbd · schema v1 · pii pii-v1
Full breach record for Maryland Medical Center/Dr. Morrill →On November 3, 2016, a cyber-attacker accessed Maryland Medical Center/Dr. Morrill's (MD) practice desktop computer system and deployed ransomware, denying access until a ransom was paid. Approximately 10,000 individuals were affected. Compromised data included patient names, dates of birth, and Social Security numbers contained in test-result correspondence. The CE recovered via backup, quarantined viruses, implemented network controls and device pre-approval procedures, and sanctioned the responsible employee. HHS OCR verified corrective actions. Submitted to HHS on 2016-12-28.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 3, 2016
Begins
Nov 3, 2016
Discovered
Dec 28, 2016
Filed
vs. sector median
5 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.