Bryan County Ambulance Authority
bd_c0911c293e9d4369 · schema v1 · pii pii-v1
Full breach record for Bryan County Ambulance Authority →Bryan County Ambulance Authority (BCAA), an Oklahoma emergency medical services provider, reported to HHS OCR on 2022-05-18 a Hacking/IT Incident (ransomware attack) affecting 14,273 individuals. Ransomware encrypted files on BCAA's network server containing patient ePHI. OCR found BCAA failed to conduct a compliant risk analysis. BCAA agreed to a $90,000 settlement and a 3-year corrective action plan — the first enforcement action under OCR's Risk Analysis Initiative. No business associate was involved.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
May 18, 2022
Filed
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Montana State AGbd_a102d13b31e69ca82022-05-18Verified
- Washington State AGbd_80051841300801102022-05-24 · +6dVerified
- Illinois State AGbd_259347935a0ec7002022-01-01 · +137dCandidate
- HHS OCR enforcementbd_b00186924c01427f2024-10-31 · +897dVerified by operator
Filing propagation · 5 filings · 4 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Oct 31 — a 1034-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.