Barton Oaks Dental Group
bd_bf3795582f01480b · schema v1 · pii pii-v1
Full breach record for Barton Oaks Dental Group →The covered entity (CE), Neeley-Nemeth, LLP d/b/a Barton Oaks Dental Group, reported that on March 23, 2017, it was the victim of a hacker who accessed its computer network servers and desktop computer and subsequently launched a ransomware attack. The ransomware attack encrypted protected health information (PHI), affecting 17,090 patients' records, including names, dates of birth, Social Security numbers, and medical information. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE updated its firewall and antivirus/anti-ransomware software for all servers and other electronic devices and retrained its workforce on HIPAA. OCR obtained assurances that the CE implemented these voluntary corrective actions.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 18, 2017
- Raw hash
- af56ce53bf7b4f547714fe3c41402339177beedb5211767ef0b04e7a238c4b7c
Source filing
Reporting entity
- Name
- Barton Oaks Dental Groupnorm: barton oaks dental
- Industry
- Health Care Services
Victim entity
- Name
- Barton Oaks Dental Groupnorm: barton oaks dental
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 17,090
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- Threat actor
- External
- Regulator citations
- Breach notification sent to HHSOCR obtained assurances of voluntary corrective actions
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.