DisclosureLens
TENNESSEEMalwareHealthcareHealthcareRansomwareData EncryptedCustomer Data InvolvedPHIHealth (basic)Identity (basic)Government IDHighContained

Bryan Myers, MD PC

bd_184e3752aab22f35 · schema v1 · pii pii-v1

Severity

High

Discovered

Nov 2, 2016

Filed

Dec 30, 2016

To disclose

8 weeks

Affected

13,150

Confidence

68%
Full breach record for Bryan Myers, MD PC

Bryan Myers, MD PC, Ashley DeWitt, DO PC, Michael Nobles, MD PC reported to HHS on 2016-12-30 a Hacking/IT Incident affecting 13150 individuals. Breached information located on Network Server. The covered entity discovered on November 2, 2016, that its EHR server had been infected with malware, affecting the electronic protected health information (ePHI) of 13,150 individuals. Information stored on the affected server included names, addresses, dates of birth, social security numbers, diagnoses/conditions, lab results, medications and other treatment information. The CE was able to disconnect the server from the network before any data was exfiltrated.

HIPAA clock HHS report on time8 weeks discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

discovery → filing · 8 weeks / 58 days

Nov 2, 2016

Discovered

Dec 30, 2016

Filed

vs. sector median

4 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed13,150 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.