DisclosureLens
MalwareHealthcareHealthcareRansomwareData EncryptedRansom DemandedSupply Chain (3P Vendor)Customer Data InvolvedPHIHealth (basic)Government IDIdentity (basic)MediumContained

Center for Orthopaedic Specialists

bd_1884c9e76ff496c9 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Apr 19, 2018

To disclose

Affected

Not disclosed

Linked

2 filings

Confidence

66%
Full breach record for Center for Orthopaedic Specialists

Center for Orthopaedic Specialists (COS) experienced a ransomware attack via a third-party IT vendor between Feb 18 and Mar 4, 2018. Malicious software encrypted patient data including names, DOBs, medical records, and SSNs. COS states no data was removed/exfiltrated. The affected system was taken offline. Federal law enforcement was notified. Patients are offered 24 months of identity theft protection.

Incident timeline

Feb 18, 2018

Begins

Apr 19, 2018

Filed

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings

View merged incident ↗
HHS OCRApr 18 · first
California State AG+1d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.