MalwareRansomwareData EncryptedRansom DemandedSupply Chain (3P Vendor)Customer Data InvolvedPHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Center for Orthopaedic Specialists
bd_1884c9e76ff496c9 · schema v1 · pii pii-v1
Full breach record for Center for Orthopaedic Specialists →Center for Orthopaedic Specialists (COS) experienced a ransomware attack via a third-party IT vendor between Feb 18 and Mar 4, 2018. Malicious software encrypted patient data including names, DOBs, medical records, and SSNs. COS states no data was removed/exfiltrated. The affected system was taken offline. Federal law enforcement was notified. Patients are offered 24 months of identity theft protection.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_2f486e4ca1cf8f57HHS OCRfiled 2018-04-18(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-135457
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 19, 2018
- Raw hash
- c5febd9846edc951e3e65fc9513ca3f4cd69b4cf84b557d685faca002ef95f61
Reporting entity
- Name
- Center for Orthopaedic Specialistsnorm: center for orthopaedic specialists
- Domain
- cosortho.com
Victim entity
- Name
- Center for Orthopaedic Specialistsnorm: center for orthopaedic specialists
- Domain
- cosortho.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Apr 18, 2018
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcement officials
- Third party
- via IT vendor
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.