Valley Women's Health, S.C.
bd_797f1f898fc3cd1d · schema v1 · pii pii-v1
Full breach record for Valley Women's Health, S.C. →Valley Women's Health, S.C. (IL) reported to HHS on 2017-04-19 a Hacking/IT Incident affecting 5,155 individuals. On Feb 17–18, 2017, attackers impersonating eClinicalWorks support staff used vishing calls to obtain remote access credentials. On Feb 20, EHR data was encrypted via ransomware. PHI exposed included names, dates of birth, addresses, SSNs, diagnoses, lab results, and medications (~4,903 individuals per description). The CE notified HHS, media, and the FBI, and implemented corrective measures confirmed by OCR. Breached info located on Electronic Medical Record and Network Server.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Apr 19, 2017
- Raw hash
- 55c0d0b5d136ded1c0ac8d9e93348cecd0892fa87889151da3f60fb45a6b16ee
Source filing
Reporting entity
- Name
- Valley Women's Health, S.C.norm: valley women s health sc
- Domain
- valleywomenshealth.com
- Industry
- Health Care Services
Victim entity
- Name
- Valley Women's Health, S.C.norm: valley women s health sc
- Domain
- valleywomenshealth.com
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Feb 20, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 5,155
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566 PhishingT1078 Valid AccountsT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- FBIHHS OCR
Compliance
- Time to disclose
- 8 weeks(58 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Feb 20, 2017→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.