Desert Care Family and Sports Medicine
bd_6521d9e7943cb043 · schema v1 · pii pii-v1
Full breach record for Desert Care Family and Sports Medicine →In early August 2016, ransomware infected Desert Care Family and Sports Medicine's (DCFSM) network server in Arizona, encrypting all data including patient records. DCFSM engaged its IT provider and Data Doctors but could not break one of two encryption variants and was unable to recover patient data. Authorities (Casa Grande PD, FBI) were notified. DCFSM reported the breach as affecting over 500 individuals. Substitute and media notification was provided. In response, DCFSM added off-site backup, retrained staff, and obtained a new server. DCFSM closed December 20, 2016; submitted to HHS OCR on that date. Location: Network Server.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Dec 20, 2016
- Raw hash
- 3c82b506baf7fd4c7844d859efead2d5a6a5bd6d926e44daa5bfd663dfd159ad
Source filing
Reporting entity
- Name
- Desert Care Family and Sports Medicinenorm: desert care family and sports medicine
- Industry
- Health Care Services
Victim entity
- Name
- Desert Care Family and Sports Medicinenorm: desert care family and sports medicine
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Aug 1, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 500
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- OCR provided technical assistance regarding the Security Rule risk analysis and risk management provisions.DCFSM notified the Casa Grande Police Department and the FBI.
Compliance
- Time to disclose
- 20 weeks(141 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Aug 1, 2016→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.