CALIFORNIAMalwareHealthcareHealthcareRansomwareCustomer Data InvolvedData EncryptedRansom DemandedHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTHighResolved
USC Keck and Norris Hospitals
bd_4b80f8a85006f5c9 · schema v1 · pii pii-v1
Full breach record for USC Keck and Norris Hospitals →USC Keck and Norris Hospitals (CA) reported to HHS on 2016-09-21 a Hacking/IT Incident (ransomware) affecting 16,000 individuals. On August 1, 2016, ransomware encrypted files on two network servers storing ePHI including names, demographic information, dates of birth, treatment information, diagnoses, and in some cases Social Security numbers. The CE shut down impacted servers, restored data from backups without paying ransom, and implemented additional malware prevention measures. OCR investigated and obtained assurances of corrective action.
HIPAA clock✓ HHS notified7 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_23d56cd429c85c34California State AGfiled 2016-09-20(1d gap)Candidate
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Sep 21, 2016
- Raw hash
- 3d050bf8740146abe47e18854e142d8ea05cd3f4fb5e19da291146463eda7889
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- USC Keck and Norris Hospitalsnorm: usc keck and norris hospitals
- Industry
- Health Care Services
Victim entity
- Name
- USC Keck and Norris Hospitalsnorm: usc keck and norris hospitals
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Aug 1, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 16,000
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- HHS OCR investigation; CE implemented corrective actions; OCR obtained assurances of remediation.
Compliance
- Time to disclose
- 7 weeks(51 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Aug 1, 2016→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.