FLMalwareHealthcareHealthcareRansomwareData EncryptedCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNTMediumResolved
FABEN Obstetrics and Gynecology
bd_aac45daf11455525 · schema v1 · pii pii-v1
Full breach record for FABEN Obstetrics and Gynecology →FABEN Obstetrics and Gynecology, LLC reported to HHS on 2019-01-18 a Hacking/IT Incident affecting 6092 individuals. Breached information located on Network Server. Ransomware infiltrated ePHI on its information system, affecting demographic, clinical, financial, and health insurance information. The CE encrypted servers, revised VPN procedures, enhanced backups, strengthened user termination, and retrained employees.
HIPAA clockDiscovered Nov 21, 2018 → Notified Jan 18, 201958d ✓ HHS notified8 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed6,092 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jan 18, 2019
- Raw hash
- edc22abd3c8a652bded9418dccec6a3b0720fc9822e8eb1073d7272c8fd6dca6
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- FABEN Obstetrics and Gynecologynorm: faben obstetrics and gynecology
- Domain
- fabenobgyn.com
- Industry
- Health Care Services
Victim entity
- Name
- FABEN Obstetrics and Gynecologynorm: faben obstetrics and gynecology
- Domain
- fabenobgyn.com
- Industry
- Healthcaresource default
Incident
- Discovered
- Nov 21, 2018
- Materiality determined
- —
- Notification sent
- Jan 18, 2019
- Affected individuals
- 6,092
- Data types
- PHIHEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 8 weeks(58 days from discovery to filing)
- Compliance flags
- HHS notified · 58dHIPAA 60-day OK · 58d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Nov 21, 2018→ Notified: Jan 18, 201958d regulatory submission HHS notified HIPAA Discovered: Nov 21, 2018→ Notified: Jan 18, 201958d 60 days HIPAA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.