MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Marin Medical Practice Concepts, Inc.
bd_b91e1f8c7919dfc3 · schema v1 · pii pii-v1
Full breach record for Marin Medical Practice Concepts, Inc. →Marin Medical Practice Concepts, Inc. (MMPC), a third-party EMR provider for Curtis F. Robinson, M.D. Inc., experienced a ransomware attack on July 26, 2016. Patient consultation notes from July 11-26, 2016, were lost due to a backup failure during restoration. No evidence of patient data viewing or transfer was found. MMPC notified law enforcement and secured its network. Curtis F. Robinson, M.D. Inc. issued breach notifications to affected patients on September 14, 2016.
California clockDiscovered Jul 27, 2016 → Notified Sep 14, 201649d ✓ CA 60-day OK11 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_3ab9835d9e237921California State AGfiled 2016-10-30(16d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-64418
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 14, 2016
- Raw hash
- b3d03d414cf30506bab48538b8af89e4b4bf83d9ae67057eff21e561bf53d29e
Reporting entity
- Name
- Curtis F. Robinson, M.D. Inc.norm: curtis f robinson md
Victim entity
- Name
- Marin Medical Practice Concepts, Inc.norm: marin medical practice concepts
Incident
- Discovered
- Jul 27, 2016
- Materiality determined
- —
- Notification sent
- Sep 14, 2016
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Initial access
- external_remote_services
Compliance
- Time to disclose
- 11 weeks(79 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 49d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 27, 2016→ Notified: Sep 14, 201649d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.