Discovery Practice Management, Inc.
bd_acce4d009f031d91 · schema v1 · pii pii-v1
Full breach record for Discovery Practice Management, Inc. →Discovery Practice Management, Inc., a California-based business associate, reported to HHS on 2021-06-05 a ransomware attack affecting the PHI of 12,859 individuals. Breached information was located in Email systems. Exposed data included names, addresses, dates of birth, Social Security numbers, driver's license numbers, medical record numbers, diagnoses, prescription information, and health insurance and financial information. The BA notified HHS, affected individuals, and the media, and provided substitute notice. Mitigation included additional administrative and technical safeguards and staff retraining.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_6265e4db9d71ea1fCalifornia State AGfiled 2021-07-01(26d gap)Verified by operator
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jun 5, 2021
- Raw hash
- ca233d022ab37afabc3d1e51e2c1c5b95d65cdcefa101b42ca3fb3d6af59b82d
Source filing
Reporting entity
- Name
- Discovery Practice Management, Inc.norm: discovery practice management
- Industry
- Business Associate
Victim entity
- Name
- Discovery Practice Management, Inc.norm: discovery practice management
- Industry
- Business Associate
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 12,859
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTAUTHENTICATION
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- HHS OCR notified
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.