GAHackingHealthcareHealthcareStolen CredentialsCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICMediumContained
Vascular Surgical Associates
bd_a9d0f41f1e7427f5 · schema v1 · pii pii-v1
Full breach record for Vascular Surgical Associates →Vascular Surgical Associates reported to HHS on 2016-11-10 a Hacking/IT Incident affecting 36496 individuals. Breached information located on Network Server. Unauthorized third parties gained access via an administrative account set up by its EHR vendor, installed software to hide activity, and obtained PHI including patient names, addresses, dates of birth, and health diagnoses.
HIPAA clock✓ HHS notified8 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed36,496 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Nov 10, 2016
- Raw hash
- 980fcac862d39392c0e9947d4d2d63edd52d98d494ec459dcb87383ea3b6517e
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Vascular Surgical Associatesnorm: vascular surgical associates
- Domain
- vascularsurgical.com
- Industry
- Health Care Services
Victim entity
- Name
- Vascular Surgical Associatesnorm: vascular surgical associates
- Domain
- vascularsurgical.com
- Industry
- Healthcaresource default
Incident
- Discovered
- Sep 13, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 36,496
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1056 Input Capture
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(58 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Sep 13, 2016→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.