CTHackingHealthcareHealthcareCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNTMediumResolved
Stamford Podiatry Group
bd_d13e14598df1e0a4 · schema v1 · pii pii-v1
Full breach record for Stamford Podiatry Group →Stamford Podiatry Group .P.C. reported to HHS on 2016-05-25 a Hacking/IT Incident affecting 40,491 individuals. Breached information located on Network Server. Unauthorized individuals gained privileged access to the server between Feb 2 and April 14, 2016, exposing demographic, financial, and clinical data. The entity retrained staff, rebuilt its IT environment, and implemented new risk management policies.
HIPAA clock✓ HHS notified6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_fedbabc63e3bc82dMontana State AGfiled 2016-05-24(1d gap)Verified
- bd_a2b186e0a8fd0ad2Oregon State AGfiled 2016-06-20(26d gap)Verified by operator
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 25, 2016
- Raw hash
- 5e2244747ce507bf61b9e9dc6bc8c21a34e1f7e8be9c3149fce795f80f3ba52c
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Stamford Podiatry Groupnorm: stamford podiatry
- Domain
- stamfordpodiatry.com
- Industry
- Health Care Services
Victim entity
- Name
- Stamford Podiatry Groupnorm: stamford podiatry
- Domain
- stamfordpodiatry.com
- Industry
- Healthcaresource default
Incident
- Discovered
- Apr 14, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 40,491
- Data types
- PHIHEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 6 weeks(41 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Apr 14, 2016→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.