MASSACHUSETTSMalwareHealthcareHealthcareRansomwareGandcrabBusiness Associate (HIPAA)Customer Data InvolvedData ExfiltratedData EncryptedRansom DemandedDelayed DiscoveryPHIHEALTH_BASICHighContained
Doctors' Management Service, Inc
bd_93af1e4de88761ea · schema v1 · pii pii-v1
Full breach record for Doctors' Management Service, Inc →Doctors Management Services, Inc. reported to HHS on 2019-04-22 a Hacking/IT Incident affecting 206,695 individuals. Breached information located on Network Server. The incident involved GandCrab ransomware encrypting files and exfiltrating data. Initial access occurred 2017-04-01; detected 2018-12-24. $100,000 settlement reached with OCR.
HIPAA clockDiscovered Dec 24, 2018 → Notified Apr 22, 2019119d ✗ HIPAA 60-day late17 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_1d84cc65754441c1Montana State AGfiled 2019-04-22Verified
- bd_525d9e853fad41d7Oregon State AGfiled 2019-04-24(2d gap)Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Apr 22, 2019
- Raw hash
- b8a9593f56873a66ede91c88743e7011535a6bb54afebda17aaf4c6beccc2290
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Doctors' Management Service, Incnorm: doctors management service
- Domain
- doctorsmanagementservice.org
- Industry
- Health Care Services
Victim entity
- Name
- Doctors' Management Service, Incnorm: doctors management service
- Domain
- doctorsmanagementservice.org
- Industry
- Healthcaresource default
Incident
- Discovered
- Dec 24, 2018
- Materiality determined
- —
- Notification sent
- Apr 22, 2019
- Affected individuals
- 206,695
- Data types
- PHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- HHS OCR announced a settlementHHS OCR began its investigation in April 2019
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 17 weeks(119 days from discovery to filing)
- Compliance flags
- HIPAA 60-day late · 119dHHS notified · 119d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Dec 24, 2018→ Notified: Apr 22, 2019119d 60 days HIPAA 60-day late HIPAA Discovered: Dec 24, 2018→ Notified: Apr 22, 2019119d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.