East Central Kansas Area Agency on Aging
bd_dda36e356e19059d · schema v1 · pii pii-v1
Full breach record for East Central Kansas Area Agency on Aging →On September 5, 2017, ransomware encrypted files in East Central Kansas Area Agency on Aging's Microsoft Azure environment. The breach affected PHI of 8,000 individuals (HHS-reported count: 8,750), including names, dates of birth, addresses, Social Security numbers, and Medicaid numbers stored on a network server. The CE notified HHS, affected individuals, and the media. Remediation included engaging a cybersecurity firm, deploying cloud security software, resetting passwords, updating remote access procedures, and employee training. OCR obtained documented assurances of corrective actions.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 5, 2017
Begins
Sep 5, 2017
Discovered
Oct 31, 2017
Filed
vs. sector median
5 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.