Waco Otolaryngology Associates
bd_f6b564df4d9eb635 · schema v1 · pii pii-v1
Full breach record for Waco Otolaryngology Associates →Waco Otolaryngology Associates d/b/a Waco Ear, Nose & Throat (TX) reported to HHS OCR on 2017-08-28 a Hacking/IT Incident affecting 500 individuals (per HHS portal listing; web description states 38,427 actual individuals affected). A ransomware attack against parent company Little River Healthcare encrypted ePHI stored on network servers. Data exposed included names, dates of birth, addresses, SSNs, lab results, medications, diagnoses, and treatment information. The covered entity subsequently separated from Little River Healthcare, migrated systems, performed a new risk analysis, and implemented additional security measures.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Aug 28, 2017
- Raw hash
- 51cb59cf6e537b758529f4d2153d5af843b6ce2c8e0f1ea65959db6e5e86bee2
Source filing
Reporting entity
- Name
- Waco Otolaryngology Associatesnorm: waco otolaryngology associates
- Industry
- Health Care Services
Victim entity
- Name
- Waco Otolaryngology Associatesnorm: waco otolaryngology associates
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 500
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access· Little River Healthcare
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- Little River HealthcareExternalFinancial
- Regulator citations
- HHS Office for Civil Rights (OCR) notifiedOCR investigation conductedCovered entity separated from Little River Healthcare during OCR investigationCovered entity provided evidence of additional security measures to OCR
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.