FLHackingHealthcareHealthcareBusiness Associate (HIPAA)Customer Data InvolvedData ExfiltratedPHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTHighContained
Medical Information Management Systems, LLC
bd_5de38dcc9a6937e9 · schema v1 · pii pii-v1
Full breach record for Medical Information Management Systems, LLC →Medical Information Management Systems, LLC reported to HHS on 2017-02-09 a Hacking/IT Incident affecting 11707 individuals. Breached information located on Network Server. A third party gained unauthorized access to the network, including the BA's server, on March 30, 2016. The incident compromised ePHI including patient names, DOBs, addresses, health insurance info, clinical info, and SSNs.
HIPAA clock✓ HHS notified34 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed11,707 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Feb 9, 2017
- Raw hash
- 7bcf8acb18b4315e7da40c353f01d70f51e98e53642b71fba380b6b2211070d4
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Medical Information Management Systems, LLCnorm: medical information management
- Industry
- Health Care Services
Victim entity
- Name
- Medical Information Management Systems, LLCnorm: medical information management
- Industry
- Healthcaresource default
Incident
- Discovered
- Jun 13, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 11,707
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified HHS (notice was not timely)OCR provided technical assistance regarding the BA’s obligations to conduct a comprehensive and current security risk analysis and implement a corresponding risk management/mitigation plan
- Third party
- via Valley Anesthesiology and Pain Consultantsbusiness associate
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 34 weeks(241 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jun 13, 2016→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.