NCHackingHealthcareHealthcarePhishingStolen CredentialsCustomer Data InvolvedData ExfiltratedPHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHighContained
Morehead Memorial Hospital
bd_84856a782283f7b5 · schema v1 · pii pii-v1
Full breach record for Morehead Memorial Hospital →Morehead Memorial Hospital reported to HHS on 2017-09-15 a Hacking/IT Incident affecting 66,000 individuals. Breached information located on Email. Phishing emails compromised employee accounts, exposing PHI including treatment, payment, names, and SSNs for 1,200 individuals. Navigant Consulting investigated. Remediation included password resets, enhanced training, and internal reporting tools.
HIPAA clockDiscovered Jun 1, 2017 → Notified Sep 15, 2017106d ✗ HIPAA 60-day late15 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_0b0e057295ec33c5Montana State AGfiled 2017-09-15Candidate
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Sep 15, 2017
- Raw hash
- d8a45b7d24c252e384a7d1da6a2328973ffb1831b38455a58e1e07382ee1e019
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Morehead Memorial Hospitalnorm: morehead memorial hospital
- Industry
- Health Care Services
Victim entity
- Name
- Morehead Memorial Hospitalnorm: morehead memorial hospital
- Industry
- Healthcaresource default
Incident
- Discovered
- Jun 1, 2017
- Materiality determined
- —
- Notification sent
- Sep 15, 2017
- Affected individuals
- 66,000
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 15 weeks(106 days from discovery to filing)
- Compliance flags
- HIPAA 60-day late · 106dHHS notified · 106d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jun 1, 2017→ Notified: Sep 15, 2017106d 60 days HIPAA 60-day late HIPAA Discovered: Jun 1, 2017→ Notified: Sep 15, 2017106d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.