FLHackingHealthcareHealthcareData ExfiltratedCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASICCriticalResolved
21st Century Oncology
bd_fcbda5a17a2f0c7e · schema v1 · pii pii-v1
Full breach record for 21st Century Oncology →21st Century Oncology, Inc. reported to HHS on 2016-03-04 a Hacking/IT Incident affecting 2,213,597 individuals. Breached information located on Network Server. The attacker accessed the SQL database via remote desktop protocol starting October 3, 2015. Patient names, SSNs, diagnoses, and insurance info were exposed. 21CO settled for $2.3 million and implemented a corrective action plan.
HIPAA clockDiscovered Oct 3, 2015 → Notified Mar 4, 2016153d ✗ HIPAA 60-day late22 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_231b0f2f48d86b56Washington State AGfiled 2016-03-04Verified
- bd_71143f2f3db9e047California State AGfiled 2016-03-04Verified
- bd_f97670eab77986b1Montana State AGfiled 2016-03-14(10d gap)Verified by operator
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 4, 2016
- Raw hash
- 9d4e5ee60a3ff40a969f214ca9d8a7cf0a8fd78a4be856d52c48e3bec258db1a
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- 21st Century Oncologynorm: 21st century oncology
- Domain
- 21co.com
- Industry
- Health Care Services
Victim entity
- Name
- 21st Century Oncologynorm: 21st century oncology
- Domain
- 21co.com
- Industry
- Healthcaresource default
Incident
- Discovered
- Oct 3, 2015
- Materiality determined
- —
- Notification sent
- Mar 4, 2016
- Affected individuals
- 2,213,597
- Data types
- PHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified HHS Office for Civil Rights (OCR)Settlement with OCR approved by Bankruptcy Court
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 22 weeks(153 days from discovery to filing)
- Compliance flags
- HIPAA 60-day late · 153dHHS notified · 153d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Oct 3, 2015→ Notified: Mar 4, 2016153d 60 days HIPAA 60-day late HIPAA Discovered: Oct 3, 2015→ Notified: Mar 4, 2016153d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.