Valley Anesthesiology Consultants, Inc.
bd_ebf01ca47ea1047c · schema v1 · pii pii-v1
Full breach record for Valley Anesthesiology Consultants, Inc. →Valley Anesthesiology Consultants, Inc. d/b/a Valley Anesthesiology and Pain Consultants (AZ) reported to HHS on 2016-08-12 a Hacking/IT Incident affecting 882,590 individuals. On March 30, 2016, a third party may have gained unauthorized access via remote desktop protocol using accounts with administrator privileges across the CE's network servers. Nine foreign IPs were identified and blacklisted; 15 suspicious local and 3 admin accounts were found potentially compromised. Breached ePHI included demographic and clinical information. OCR provided technical assistance on risk analysis, training, and access controls.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_528c463d467fa4ddOregon State AGfiled 2016-08-12Candidate
- bd_62ea62ba052757f3California State AGfiled 2016-08-12Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Aug 12, 2016
- Raw hash
- 2d87ab69b8357d54741bd5810f682f29896aa5ef8b76ae57be008c9278ff9515
Source filing
Reporting entity
- Name
- Valley Anesthesiology Consultants, Inc.norm: valley anesthesiology consultants
- Industry
- Health Care Services
Victim entity
- Name
- Valley Anesthesiology Consultants, Inc.norm: valley anesthesiology consultants
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Mar 30, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 882,590
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1021.001 Remote Desktop Protocol
- Threat actor
- External
- Regulator citations
- OCR provided technical assistance regarding comprehensive security risk analysis and risk management/mitigation planOCR provided TA regarding security awareness training program documentationOCR requested clarification on user access review procedures for non-ePHI applications
- Initial access
- external_remote_services
Compliance
- Time to disclose
- 19 weeks(135 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Mar 30, 2016→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.