Doctors' Management Service, Inc
bd_1d84cc65754441c1 · schema v1 · pii pii-v1
Full breach record for Doctors' Management Service, Inc →2 incidents on fileDoctors’ Management Service, Inc. (DMS) disclosed a ransomware incident involving the GandCrab variant. Initial unauthorized access occurred on April 1, 2017 via RDP; technical issues were first noticed on December 24, 2018. The incident impacted personal health information (PHI) including names, SSNs, DOBs, driver's licenses, and medical data. No evidence of data exfiltration was found, but activity could not be ruled out. DMS restored data from backups, engaged forensic investigators, notified law enforcement and HHS, and offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 1, 2017
Begins
Dec 24, 2018
Discovered
Apr 22, 2019
Filed
vs. sector median
+4 wks slower
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- HHS OCRbd_93af1e4de88761ea2019-04-22Verified
- Massachusetts State AGbd_31de1d03468648ee2019-04-23 · +1dVerified
- Oregon State AGbd_525d9e853fad41d72019-04-24 · +2dVerified
- New Hampshire State AGbd_2817736d1e5cea712019-05-28 · +36dVerified
Show 1 more filing ↓Show fewer ↑up to 1653d gap
- HHS OCR enforcementbd_928833438d5c3c322023-10-31 · +1653dVerified by operator
Filing propagation · 6 filings · 4 states
View merged incident ↗Pattern: first filing Apr 22 (MA), last Oct 31 — a 1653-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.