Erskine Family Dentistry
bd_874d2d1fd088b7b3 · schema v1 · pii pii-v1
Full breach record for Erskine Family Dentistry →Erskine Family Dentistry (Indiana) reported to HHS on 2013-05-21 a Hacking/IT Incident affecting 2,723 individuals. A malicious email containing a virus was opened on a practice desktop computer, affecting computers storing PHI. PHI involved included patients' names, addresses, dates of birth, Social Security numbers, credit card numbers, claims information, and treatment information. The CE confirmed the virus did not penetrate encrypted PHI programs, wiped all affected machines, installed a new antivirus tool, stored PHI only in encrypted programs, retrained staff, and notified HHS, media, and affected individuals.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 21, 2013
- Raw hash
- 56fcd61a4f3eaaccc1301c0390386a8ef25ecf5906dabf59640aed7defead26f
Source filing
Reporting entity
- Name
- Erskine Family Dentistrynorm: erskine family dentistry
- Industry
- Health Care Services
Victim entity
- Name
- Erskine Family Dentistrynorm: erskine family dentistry
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 2,723
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566 PhishingT1204.002 User Execution: Malicious FileT1204 User Execution
- Threat actor
- External
- Regulator citations
- HHS OCR — breach notification submitted; OCR obtained written documentation of corrective actions
- Initial access
- phishing_attachment
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.