NCHackingHealthcareHealthcareBrute ForceCustomer Data InvolvedData ExfiltratedDelayed DiscoveryHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTHighResolved
Pasquotank-Camden Emergency Medical Service
bd_66731734023c7501 · schema v1 · pii pii-v1
Full breach record for Pasquotank-Camden Emergency Medical Service →Pasquotank-Camden Emergency Medical Services (NC) reported to HHS on 2019-02-28 a Hacking/IT Incident affecting 20,420 individuals. On December 14, 2018, the CE discovered data was missing from its administrative network server. A forensic investigation determined the breach was caused by a brute force attack by a hacker located in Eastern Europe. PHI including names, billing records, medical information, Social Security numbers, and dates of birth was exposed. The CE restored data from backup and implemented multiple corrective actions.
HIPAA clockDiscovered Dec 14, 2018 → Notified Feb 21, 201969d ✗ HIPAA 60-day late11 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed20,420 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Feb 28, 2019
- Raw hash
- c3534e981edaaf91743714c04981bab47ff7311e446d708877bbeca13c9ad258
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Pasquotank-Camden Emergency Medical Servicenorm: pasquotank camden emergency medical service
- Industry
- Health Care Services
Victim entity
- Name
- Pasquotank-Camden Emergency Medical Servicenorm: pasquotank camden emergency medical service
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Dec 14, 2018
- Materiality determined
- —
- Notification sent
- Feb 21, 2019
- Affected individuals
- 20,420
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1110 Brute ForceT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- OCR provided technical assistance regarding how to determine the start date of a breach and obtained assurances that the CE implemented the corrective actions listed above.
- Initial access
- external_remote_services
Compliance
- Time to disclose
- 11 weeks(76 days from discovery to filing)
- Compliance flags
- HIPAA 60-day late · 69dHHS notified · 69d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Dec 14, 2018→ Notified: Feb 21, 201969d 60 days HIPAA 60-day late HIPAA Discovered: Dec 14, 2018→ Notified: Feb 21, 201969d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.