Pacific Alliance Medical Center
bd_69dd13eaaf8533d7 · schema v1 · pii pii-v1
Full breach record for Pacific Alliance Medical Center →Pacific Alliance Medical Center (CA) reported to HHS OCR on 2017-08-10 a Hacking/IT Incident (malware/ransomware attack) affecting 266,123 individuals. Breached information was located on a Network Server. PHI exposed included names, dates of birth, addresses, Social Security numbers, driver's license information, claims information, diagnoses, medications, lab results, and medical images. The CE notified HHS, affected individuals, and the media. Following OCR's investigation, the CE strengthened administrative and technical safeguards to enhance protection of PHI.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_df2bbf3bcd85420eCalifornia State AGfiled 2017-08-11(1d gap)Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Aug 10, 2017
- Raw hash
- 0058db65691a2b00270f00fb78ca396529428ff0013e99fa3ddc0d9415251d04
Source filing
Reporting entity
- Name
- Pacific Alliance Medical Centernorm: pacific alliance medical center
- Domain
- caribbeanmedicalcenter.com
- Industry
- Health Care Services
Victim entity
- Name
- Pacific Alliance Medical Centernorm: pacific alliance medical center
- Domain
- caribbeanmedicalcenter.com
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 266,123
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- HHS OCR investigation completed; CE required to enhance PHI safeguarding practices
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.