MOMalwareHealthcareHealthcareRansomwareCustomer Data InvolvedData EncryptedRansom DemandedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICHighResolved
Capital Region Medical Center
bd_7ab7349dfcd1fd47 · schema v1 · pii pii-v1
Full breach record for Capital Region Medical Center →Capital Region Medical Center (Jefferson City, MO) reported to HHS OCR on 2022-03-11 a ransomware incident affecting 17,578 individuals. Breached information was located on a network server and included names, addresses, dates of birth, driver's license numbers, Social Security numbers, medical diagnoses/conditions, and other treatment information. The CE notified HHS, affected individuals, and the media, posted substitute notice, and implemented additional administrative, technical, and security safeguards, including staff retraining.
HIPAA clock✓ HHS notified
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_9adc7a8104cf5c60Maine State AGfiled 2022-03-25(14d gap)Verified
- bd_c8480a3cbc771a48Montana State AGfiled 2022-03-25(14d gap)Candidate
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 11, 2022
- Raw hash
- 1fd719a7c607a260222456672e5961aa1a41fc1d5d4ae7f46f6fe88e897389f6
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Capital Region Medical Centernorm: capital region medical center
- Domain
- crmc.org
- Industry
- Health Care Services
Victim entity
- Name
- Capital Region Medical Centernorm: capital region medical center
- Domain
- crmc.org
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Dec 24, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 17,578
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- HHS OCR notified
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Dec 24, 2021→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.