ALMalwareHealthcareFinancial ServicesHealthcareRansomwareCustomer Data InvolvedData EncryptedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTHighResolved
Jemison Internal Medicine, PC
bd_f9719e1e64c28a6c · schema v1 · pii pii-v1
Full breach record for Jemison Internal Medicine, PC →On December 20, 2017, Jemison Internal Medicine, PC (AL) discovered ransomware had encrypted files in its EMR system. Forensic investigation by Altep revealed unauthorized access via RDP, exposing PHI for 6,550 individuals including names, addresses, birthdates, driver's license numbers, SSNs, insurance information, and medical information. The CE reset passwords, implemented MFA for remote access, and updated HIPAA security policies with OCR technical assistance. Breach reported to HHS on 2018-02-16. Breached information located on Network Server.
HIPAA clock✓ HHS notified8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed6,550 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Feb 16, 2018
- Raw hash
- 62f3d4e8b466c29c3473fe7a0810b0cf7e44b76b0330a9051429d1848564c9c9
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Jemison Internal Medicine, PCnorm: jemison internal medicine
- Industry
- Insurance — Health
Victim entity
- Name
- Jemison Internal Medicine, PCnorm: jemison internal medicine
- Industry
- Insurance — Health
- Industry
- Healthcaresource defaultFinancial Servicesllm
Incident
- Discovered
- Dec 20, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 6,550
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1486 Data Encrypted for ImpactT1021.001 Remote Desktop Protocol
- Threat actor
- ExternalFinancial
- Regulator citations
- HHS OCR notified; OCR provided technical assistance; OCR obtained assurances of corrective action implementation
- Initial access
- external_remote_services
Compliance
- Time to disclose
- 8 weeks(58 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Dec 20, 2017→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.