Reeve-Woods Eye Center
bd_299d3c24ce7f01b2 · schema v1 · pii pii-v1
Full breach record for Reeve-Woods Eye Center →Reeve-Woods Eye Center (CA) reported to HHS OCR on 2014-11-15 a malware incident affecting 30,000 individuals (the web description references 43,000). Malware infiltrated the CE's electronic network approximately August 1 – September 17, 2014, causing screenshots and keystrokes to be exfiltrated outside the network. ePHI exposed included names, SSNs, dates of birth, addresses, phone numbers, dates of service, insurance information, diagnosis codes, treatment information, and medical histories. The CE cooperated with the FBI, cleared the malware, and strengthened technical security controls. Breached information located on Network Server.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_22a2ddc8c98ad3dcCalifornia State AGfiled 2014-11-14(1d gap)Verified by operator
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Nov 15, 2014
- Raw hash
- 3252795d0627a91c013353e1d949efa2c4630351eeb96f4f5abf04d0ca4cb758
Source filing
Reporting entity
- Name
- Reeve-Woods Eye Centernorm: reeve woods eye center
- Industry
- Health Care Services
Victim entity
- Name
- Reeve-Woods Eye Centernorm: reeve woods eye center
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 30,000
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1056 Input CaptureT1113 Screen CaptureT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- FBIHHS OCR
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.