Hackensack Sleep and Pulmonary Center
bd_1affb44160cc18f9 · schema v1 · pii pii-v1
Full breach record for Hackensack Sleep and Pulmonary Center →Hackensack Sleep and Pulmonary Center (NJ) reported to HHS OCR on 2017-11-28 a Hacking/IT Incident (ransomware) affecting 16,474 individuals. A ransomware virus encrypted electronic medical record files on a network server; the attacker demanded bitcoin payment to unlock files. The CE declined to pay and restored records from an offline backup. ePHI exposed included names, addresses, DOB, driver's license numbers, SSNs, email addresses, lab results, medications, diagnoses, and health insurance information. The CE notified HHS, affected individuals, media, and the NJ Cyber Unit, and subsequently adopted encryption and strengthened password controls. OCR obtained corrective action assurances.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Nov 28, 2017
- Raw hash
- 63760239fbdff3ca3ef1777dbd35218cc6c02016e10f42a9bd57c4ae487743fd
Source filing
Reporting entity
- Name
- Hackensack Sleep and Pulmonary Centernorm: hackensack sleep and pulmonary center
- Industry
- Health Care Services
Victim entity
- Name
- Hackensack Sleep and Pulmonary Centernorm: hackensack sleep and pulmonary center
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 16,474
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 ChannelT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported to HHS OCRNotified New Jersey Cyber UnitOCR obtained assurances of corrective actions
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.