Burr & Forman LLP
bd_b7faab01c06cf85b · schema v1 · pii pii-v1
Full breach record for Burr & Forman LLP →Burr & Forman LLP, an Alabama-based law firm acting as a HIPAA business associate, reported a ransomware incident on 2024-01-09 affecting protected health information of 19,893 individuals. PHI involved included names, dates of birth, Social Security numbers, claims and financial information, and treatment information, stored on a network server. The firm notified HHS, affected individuals, and the media; posted substitute notice on its website; offered complimentary credit monitoring and identity protection services; and implemented additional technical safeguards.
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_936f18390c8af16dIndiana State AGfiled 2024-01-09Verified
- bd_0d5c7d285321c138Maine State AGfiled 2024-01-10(1d gap)Verified
- bd_2a488a25ec65f451Vermont State AGfiled 2024-01-10(1d gap)Verified
- bd_9c70d44242deebc5Montana State AGfiled 2024-01-10(1d gap)Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jan 9, 2024
- Raw hash
- 069c2b5c18e6f2e8cf2a004f088c029d42cd676fe6fa5d8a6d26b89b8bfc784b
Source filing
Reporting entity
- Name
- Burr & Forman LLPnorm: burr forman
- Industry
- Legal services
Victim entity
- Name
- Burr & Forman LLPnorm: burr forman
- Industry
- Legal services
- Industry
- Healthcaresource defaultProfessional Servicesllm
Incident
- Discovered
- Oct 23, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 19,893
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIALHEALTH_BASIC
- Attack vector
- Ransomware
- Threat actor
- ExternalFinancial
- Regulator citations
- HHS OCR breach report
- Third party
- via Burr & Forman LLP
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Oct 23, 2023→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.