Maine General Health
bd_d5ea91f5b6ff8fb8 · schema v1 · pii pii-v1
Full breach record for Maine General Health →Maine General Health (ME) reported to HHS OCR on 2015-12-08 a Hacking/IT Incident affecting approximately 120,247 individuals. On November 13, 2015, the FBI informed the CE it had discovered CE data on an online Russian message board. Internet-browsing activity on a CE workstation led to malware infection; an intruder remotely scanned the network, stole credentials, and accessed servers containing PHI including names, demographics, dates of birth, diagnoses, treatments, medical record numbers, and health insurance IDs. Breached info resided on network servers. OCR obtained assurances of corrective action completion.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Dec 8, 2015
- Raw hash
- fd230676f3f2a18d2bf3b91f721180f55c6721fdecf283e5e3f5e0488020848f
Source filing
Reporting entity
- Name
- Maine General Healthnorm: maine general health
- Industry
- Health Care Services
Victim entity
- Name
- Maine General Healthnorm: maine general health
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Nov 13, 2015
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 120,247
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTMETADATA
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1189 Drive-by CompromiseT1078 Valid AccountsT1590 Gather Victim Network Information
- Threat actor
- ExternalFinancial
- Regulator citations
- FBI informed Maine General Health on November 13, 2015 of CE data discovered on an online Russian message board during an ongoing criminal investigation.Breach notification provided to HHS, affected individuals, and the media.OCR obtained assurances that the CE implemented corrective actions.
- Initial access
- drive_by_compromise
Compliance
- Time to disclose
- 25 days(25 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Nov 13, 2015→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.