HackingData ExfiltratedCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
QRS Music Technology
bd_1cc290f23d036e0f · schema v1 · pii pii-v1
Full breach record for QRS Music Technology →QRS, Inc., a software provider for medical practices, experienced unauthorized access to a patient portal server from August 23-26, 2021. An unknown third party accessed and potentially acquired PHI, including names, SSNs, and medical data. Gregory Brewer, MD PLLC, a business associate, notified one New Hampshire resident on October 22, 2021. QRS took the server offline, engaged forensic investigators, and implemented MFA and SIEM.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/gregory-brewer-md-pllc-20211108.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 8, 2021
- Raw hash
- 2918fc928ed168ae1c5d3cfc32d30110dbef6fab5b2e12be24b27bf91f7170d2
Reporting entity
- Name
- Gregory Brewer, MD PLLCnorm: gregory brewer md
Victim entity
- Name
- QRS Music Technologynorm: qrs music
- Domain
- qrsmusic.com
Incident
- Discovered
- Aug 26, 2021
- Materiality determined
- —
- Notification sent
- Oct 22, 2021
- Affected individuals
- 1
- Data types
- PHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(74 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.