Good Care Pediatric, LLP
bd_8abc05d5198b61a1 · schema v1 · pii pii-v1
Full breach record for Good Care Pediatric, LLP →Good Care Pediatric, LLP (NY) reported to HHS OCR on 2015-11-12 a Hacking/IT Incident affecting 2,300 individuals. A Trojan Horse virus compromised one desktop computer device, making patient billing files accessible by unauthorized individuals online from January 1 through April 3, 2014. ePHI exposed included patients' names, addresses, telephone numbers, dates of birth, and diagnosis codes. The CE remediated by shutting down external access, scanning all devices, changing passwords, encrypting billing files, and retraining staff. OCR provided technical assistance on risk analysis.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Nov 12, 2015
- Raw hash
- 91ae31a608089e1fcf5ec9ea80ef2f90701d3f1210406483dd953283d90e2bc9
Source filing
Reporting entity
- Name
- Good Care Pediatric, LLPnorm: good care pediatric
- Industry
- Health Care Services
Victim entity
- Name
- Good Care Pediatric, LLPnorm: good care pediatric
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 2,300
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1204 User ExecutionT1071 Application Layer ProtocolT1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- OCR opened an investigation and provided technical assistance regarding risk analyses and procedures for guarding against, detecting, and reporting malicious software.
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.