Maffi Clinics
bd_3305fcc273c2906f · schema v1 · pii pii-v1
Full breach record for Maffi Clinics →On September 11, 2018, Maffi Clinics (AZ) was the victim of a ransomware attack on its network server affecting 10,465 patients' clinical and demographic information. Maffi promptly terminated the unauthorized access point, isolated and removed the ransomware, and restored all data. No evidence was found that data was viewed or downloaded. Patient notifications were sent on February 14, 2019. OCR closed its investigation after determining Maffi is not a HIPAA covered entity or business associate.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 11, 2018
Begins
Sep 11, 2018
Discovered
Mar 6, 2019
Filed
vs. sector median
+13 wks slower
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.