Man Alive, Inc. and Lane Treatment Center, LLC
bd_2abb7f3a8851fdbf · schema v1 · pii pii-v1
Full breach record for Man Alive, Inc. and Lane Treatment Center, LLC →Man Alive, Inc. and Lane Treatment Center, LLC (MD) reported to HHS on 2016-09-08 a Hacking/IT Incident affecting 860 individuals. A cyber-attacker gained access via remote access, installed ransomware on an employee's desktop computer, and accessed the electronic patient record system, downloading patient profiles containing names, birthdates, SSNs, drug dosage info, insurance IDs, addresses, phone numbers, and employment/demographic data. Breached info located on Desktop Computer and Electronic Medical Record system. FBI was notified; corrective actions confirmed by OCR.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Sep 8, 2016
- Raw hash
- 8708f21263fd20637eedb89e15be743f191182852978c7daf8d6901ec0263771
Source filing
Reporting entity
- Name
- Man Alive, Inc. and Lane Treatment Center, LLCnorm: man alive inc and lane treatment center
- Industry
- Health Care Services
Victim entity
- Name
- Man Alive, Inc. and Lane Treatment Center, LLCnorm: man alive inc and lane treatment center
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Sep 8, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 860
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid AccountsT1041 Exfiltration Over C2 ChannelT1133 External Remote Services
- Threat actor
- ExternalFinancial
- Regulator citations
- HHS OCRFBI
- Initial access
- external_remote_services
Compliance
- Time to disclose
- ≤1 day(0 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Sep 8, 2016→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.