Coastal Cape Fear Eye Associates, P.A.
bd_6ef5d32455834110 · schema v1 · pii pii-v1
Full breach record for Coastal Cape Fear Eye Associates, P.A. →Coastal Cape Fear Eye Associates, P.A. (NC) reported to HHS OCR on 2018-02-01 a Hacking/IT Incident affecting 925 individuals. On December 5, 2017, a shared drive folder was infected with ransomware delivered via a phishing attack. Exposed PHI included names, addresses, dates of birth, phone numbers, SSNs, insurance, driver's license, Medicare info, email addresses, ethnicities, medical histories, medications, and billing histories. Breached info located on Desktop Computer and Network Server. The CE notified HHS, individuals, and media. Remediation included new hard drives, security updates, firewall resets, backup restoration, workforce retraining, and updated HIPAA policies. The practice closed April 30, 2019.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Feb 1, 2018
- Raw hash
- 5203776ebbce98aa67627c0c96e642214dcfb7cd89291e096b0582ce1e30aa25
Source filing
Reporting entity
- Name
- Coastal Cape Fear Eye Associates, P.A.norm: coastal cape fear eye associates
- Industry
- Health Care Services
Victim entity
- Name
- Coastal Cape Fear Eye Associates, P.A.norm: coastal cape fear eye associates
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Dec 5, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 925
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566 PhishingT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- HHS OCR breach notification filedOCR obtained assurances of corrective actions
- Initial access
- phishing_attachment
Compliance
- Time to disclose
- 8 weeks(58 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Dec 5, 2017→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.