AKMalwareHealthcareHealthcareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCriticalContained
State of Alaska Department of Health and Social Services
bd_1ee7eaab07f250db · schema v1 · pii pii-v1
Full breach record for State of Alaska Department of Health and Social Services →State of Alaska Department of Health and Social Services reported to HHS on 2018-06-28 a Hacking/IT Incident affecting 942,528 individuals. Breached information located on Desktop Computer, Email. The incident involved ransomware encryption and data exfiltration of ePHI including names, SSNs, and health insurance data. FBI assisted in the investigation.
HIPAA clock✓ HHS notified≤1 day discovery → filing
⚠ filing dateThe stored discovery date equals the regulator filing date, so no genuine detection date was captured.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed942,528 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jun 28, 2018
- Raw hash
- 32447f05e4485918e839837027f2a99caa96e8ac40400b27ac35cc861593cb11
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- State of Alaska Department of Health and Social Servicesnorm: state of alaska department of health and social
- Industry
- Insurance — Health
Victim entity
- Name
- State of Alaska Department of Health and Social Servicesnorm: state of alaska department of health and social
- Industry
- Healthcaresource default
Incident
- Discovered
- Jun 28, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 942,528
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified HHSOCR provided technical assistance on risk analysis, risk management, and security policies and procedures
- Initial access
- phishing_link
Compliance
- Time to disclose
- ≤1 day(0 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- filing dateThe stored discovery date equals the regulator filing date, so no genuine detection date was captured.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jun 28, 2018→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.