Orthodontic Specialists of Green Bay
bd_3107553bb850e505 · schema v1 · pii pii-v1
Full breach record for Orthodontic Specialists of Green Bay →Orthodontic Specialists of Green Bay (WI) reported to HHS OCR on 2017-04-24 a Hacking/IT Incident affecting 742 individuals. An unauthorized external actor accessed a doctor's email account between April 7–10, 2017 to monitor communications and conduct financial fraud by impersonating the doctor and requesting wire transfers. ePHI including names and treatment information was exposed. The CE notified the FBI, engaged its IT contractor, reset all employee passwords, and implemented new password management policies. OCR obtained assurances of corrective actions. Breached information located on Email.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Apr 24, 2017
- Raw hash
- d9ebb74570d58ee0d2c216cdb7b8416190832688976482cae1d48c61f595581d
Source filing
Reporting entity
- Name
- Orthodontic Specialists of Green Baynorm: orthodontic specialists of green bay
- Industry
- Health Care Services
Victim entity
- Name
- Orthodontic Specialists of Green Baynorm: orthodontic specialists of green bay
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Apr 10, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 742
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1566 PhishingT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- HHS OCRFBI
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 14 days(14 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Apr 10, 2017→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.