MNHackingHealthcareHealthcareCustomer Data InvolvedPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICHighResolved
Family Service Rochester
bd_b776becc98683e1b · schema v1 · pii pii-v1
Full breach record for Family Service Rochester →Family Service Rochester, a Minnesota healthcare provider, discovered on January 26, 2017 that an unauthorized user had accessed a computer server containing names, addresses, dates of birth, and Social Security numbers of approximately 17,037 patients. The entity terminated access to the remote desktop and the compromised "programs" account, disabled stale accounts, revised HIPAA policies, and notified HHS, affected individuals, and the media.
HIPAA clockDiscovered Jan 26, 2017 → Notified Feb 17, 201722d ✓ HIPAA 60-day OK22 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_131fbaaf18b5d663Montana State AGfiled 2017-02-17Candidate
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Feb 17, 2017
- Raw hash
- 3d30d32e9bbc0e9378c4c8aec448ebc746618c614440eee1dd180ef815a93e8b
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Family Service Rochesternorm: family service rochester
Victim entity
- Name
- Family Service Rochesternorm: family service rochester
- Industry
- Healthcare Provider
- Industry
- Healthcaresource default
Incident
- Discovered
- Jan 26, 2017
- Materiality determined
- —
- Notification sent
- Feb 17, 2017
- Affected individuals
- 17,037
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified HHSOCR obtained documented assurances that the CE implemented the corrective actions
Compliance
- Time to disclose
- 22 days(22 days from discovery to filing)
- Compliance flags
- HIPAA 60-day OK · 22dHHS notified · 22d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jan 26, 2017→ Notified: Feb 17, 201722d 60 days HIPAA 60-day OK HIPAA Discovered: Jan 26, 2017→ Notified: Feb 17, 201722d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.