Rainbow Children's Clinic
bd_b782f2248475425b · schema v1 · pii pii-v1
Full breach record for Rainbow Children's Clinic →Rainbow Children's Clinic (TX) reported to HHS OCR on 2016-10-03 a Hacking/IT Incident affecting 33,698 individuals. On August 3, 2016, a hacker accessed the clinic's network servers and launched a ransomware attack that began encrypting patient data; some patient records were irretrievably deleted. The CE shut down its system immediately, retained a forensic expert, notified HHS/individuals/media, and offered identity protection services. No misuse of personal data was identified. Post-incident, the CE deployed new anti-virus software and implemented staff security-training policies. OCR obtained assurances of corrective action. Breached information was located on Network Server.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 3, 2016
Begins
Aug 3, 2016
Discovered
Oct 3, 2016
Filed
vs. sector median
2 wks faster
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- South Carolina State AGbd_31ea4be484a9d5442016-10-12 · +9dVerified
Filing propagation · 2 filings · 2 states
View merged incident ↗Pattern: first filing Oct 3 (TX), last Oct 12 (SC) — a 9-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.