MalwareRansomwareGriefData ExfiltratedData EncryptedCustomer Data InvolvedTargetedData PublishedPHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
Central Indiana Orthopedics
bd_dfcca2999372f5fd · schema v1 · pii pii-v1
Full breach record for Central Indiana Orthopedics →Central Indiana Orthopedics experienced a ransomware attack by the Grief threat actor group in October 2021. The incident compromised the protected health information and personal data of approximately 83,705 patients. The organization detected the breach on October 16, 2021, and began notifying affected individuals and regulators in March 2022. Response efforts included engaging forensic investigators and providing credit monitoring services.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_550eb4f72b1e5e47Maine State AGfiled 2022-03-07(7d gap)Candidate
- bd_9d937bc08a111f47HHS OCRfiled 2022-03-07(7d gap)Verified
- bd_e8b63382f007b525Montana State AGfiled 2022-03-07(7d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/central-indiana-orthopedics-20220314.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 14, 2022
- Raw hash
- 69f7ada7efeaf9ff1d87736d2069bd902470d6c16611b33a29f772e34e6c2cf1
Reporting entity
- Name
- Central Indiana Orthopedicsnorm: central indiana orthopedics
Victim entity
- Name
- Central Indiana Orthopedicsnorm: central indiana orthopedics
Incident
- Discovered
- Oct 16, 2021
- Materiality determined
- —
- Notification sent
- Mar 8, 2022
- Affected individuals
- 83,705
- Data types
- PHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Ransomware· Grief
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 ChannelT1119 Automated Collection
- Threat actor
- GriefExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General's Office
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 21 weeks(149 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.