Hackensack Sleep and Pulmonary Center
bd_1affb44160cc18f9 · schema v1 · pii pii-v1
Full breach record for Hackensack Sleep and Pulmonary Center →Hackensack Sleep and Pulmonary Center (NJ) reported to HHS OCR on 2017-11-28 a Hacking/IT Incident (ransomware) affecting 16,474 individuals. A ransomware virus encrypted electronic medical record files on a network server; the attacker demanded bitcoin payment to unlock files. The CE declined to pay and restored records from an offline backup. ePHI exposed included names, addresses, DOB, driver's license numbers, SSNs, email addresses, lab results, medications, diagnoses, and health insurance information. The CE notified HHS, affected individuals, media, and the NJ Cyber Unit, and subsequently adopted encryption and strengthened password controls. OCR obtained corrective action assurances.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Nov 28, 2017
Filed
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.