GAMalwareHealthcareHealthcareRansomwareData EncryptedCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTHighContained
Mind & Motion, LLC
bd_91fa5facbf0f63a7 · schema v1 · pii pii-v1
Full breach record for Mind & Motion, LLC →Mind and Motion, LLC reported to HHS on 2018-11-30 a Hacking/IT Incident affecting 16000 individuals. Breached information located on Network Server. The incident involved ransomware (encrypted extension) and keyloggers. PHI exposed included names, addresses, DOB, SSN, and medical records. The entity reset passwords, encrypted servers/computers, and provided HIPAA training.
HIPAA clockDiscovered Nov 30, 2018 → Notified Nov 30, 20180d ✓ HHS notified≤1 day discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed16,000 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Nov 30, 2018
- Raw hash
- fabdab993ec51b0b3911df6769618b106f66071aefca711922811652b9eb1f40
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Mind & Motion, LLCnorm: mind motion
- Domain
- mindmotionservices.com
- Industry
- Health Care Services
Victim entity
- Name
- Mind & Motion, LLCnorm: mind motion
- Domain
- mindmotionservices.com
- Industry
- Healthcaresource default
Incident
- Discovered
- Nov 30, 2018
- Materiality determined
- —
- Notification sent
- Nov 30, 2018
- Affected individuals
- 16,000
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1056 Input Capture
- Threat actor
- External
- Regulator citations
- notified OCROCR provided technical guidance to the CE regarding the implementation of a risk management planOCR obtained assurances that the CE implemented the corrective actions noted above
Compliance
- Time to disclose
- ≤1 day(0 days from discovery to filing)
- Compliance flags
- HHS notified · 0dHIPAA 60-day OK · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Nov 30, 2018→ Notified: Nov 30, 20180d regulatory submission HHS notified HIPAA Discovered: Nov 30, 2018→ Notified: Nov 30, 20180d 60 days HIPAA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.