Rockford Gastroenterology Associates
bd_c05bceec9d2b4c78 · schema v1 · pii pii-v1
Full breach record for Rockford Gastroenterology Associates →Press / market disclosure — not a breach-notification filing
A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage — verify against the source.
Rockford Gastroenterology Associates notifies 147,253 patients of December 2023 cyberattack - DataBreaches.Net. Rockford Gastroenterology Associates (RGA): Rockford Gastroenterology Associates notified 147,253 patients of a cyberattack that occurred in December 2023, during which sensitive data such as medical records and patient account information was stolen. The attackers, known as RA World, demanded a ransom and eventually published the data on the dark web after the company did not pay. The official notification to patients does not mention the data leak on the dark web, leaving patients unaware of the true extent of the privacy breach. Linked ransomware group: raworld.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Dec 16, 2023
Press report
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Attack → press
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (2)
- Leak Siteraworldbd_63e48c877a505b382024-03-21 · +96dVerified by operator
- Leak Siteraworldbd_298fd7202a5678bc2023-12-20 · +5dVerified
Regulatory filings (2) · sorted by filing gap
- Illinois State AGbd_0835b12fdfde6ba02024-10-01 · +290dVerified by operator
- HHS OCRbd_b4ff254b4bf81d3a2024-10-30 · +319dVerified
Filing propagation · 3 filings
View merged incident ↗Pattern: first filing Dec 16, last Oct 30 (IL) — a 319-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- incident type + narrative only (may be machine-translated)
- discovery date
- materiality
- affected count
- data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
raworld
According to ransomware.live, RA Group, also known as RA World, first surfaced in April 2023, utilizing a custom variant of the Babuk ransomware.