Bryan Myers, MD PC, Ashley DeWitt, DO PC, Michael Nobles, MD PC
bd_184e3752aab22f35 · schema v1 · pii pii-v1
Full breach record for Bryan Myers, MD PC, Ashley DeWitt, DO PC, Michael Nobles, MD PC →Bryan Myers, MD PC, Ashley DeWitt, DO PC, Michael Nobles, MD PC reported to HHS on 2016-12-30 a Hacking/IT Incident affecting 13150 individuals. Breached information located on Network Server. The covered entity discovered on November 2, 2016, that its EHR server had been infected with malware, affecting the electronic protected health information (ePHI) of 13,150 individuals. Information stored on the affected server included names, addresses, dates of birth, social security numbers, diagnoses/conditions, lab results, medications and other treatment information. The CE was able to disconnect the server from the network before any data was exfiltrated.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Dec 30, 2016
- Raw hash
- 99d1a43584f7fbcf0c2750e98a3888e479a3f18c9547a062afac69305be26bb2
Source filing
Reporting entity
- Name
- Bryan Myers, MD PC, Ashley DeWitt, DO PC, Michael Nobles, MD PCnorm: bryan myers md pc ashley dewitt do pc michael nobles md
- Industry
- Health Care Services
Victim entity
- Name
- Bryan Myers, MD PC, Ashley DeWitt, DO PC, Michael Nobles, MD PCnorm: bryan myers md pc ashley dewitt do pc michael nobles md
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Nov 2, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 13,150
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- External
- Regulator citations
- provided breach notification to HHSOCR provided technical assistance to the CE regarding media notice and the performance of risk analysesOCR obtained assurances that the CE implemented the corrective actions listed above
Compliance
- Time to disclose
- 8 weeks(58 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Nov 2, 2016→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.