DisclosureLens
ARIZONAMalwareHealthcareHealthcareRansomwareCustomer Data InvolvedData EncryptedHealth (basic)Identity (basic)MediumResolved

Maffi Clinics

bd_3305fcc273c2906f · schema v1 · pii pii-v1

Severity

Medium

Discovered

Sep 11, 2018

Filed

Mar 6, 2019

To disclose

25 weeks

Affected

10,465

Confidence

98%
Full breach record for Maffi Clinics

On September 11, 2018, Maffi Clinics (AZ) was the victim of a ransomware attack on its network server affecting 10,465 patients' clinical and demographic information. Maffi promptly terminated the unauthorized access point, isolated and removed the ransomware, and restored all data. No evidence was found that data was viewed or downloaded. Patient notifications were sent on February 14, 2019. OCR closed its investigation after determining Maffi is not a HIPAA covered entity or business associate.

HIPAA clockDiscovered Sep 11, 2018Notified Feb 14, 2019156d HIPAA individual notice late25 weeks discovery → filing
occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.

Incident timeline

discovery → filing · 25 weeks / 176 days

Sep 11, 2018

Begins

Sep 11, 2018

Discovered

Mar 6, 2019

Filed

vs. sector median

+13 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed10,465 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.