Bryan County Ambulance Authority
ent_1819a583d7b15583cf76973f
Disclosures
5
HHS OCR enforcement · State AG · HHS OCR · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
14,273
nationwide · HHS OCR OK
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Bryan County Ambulance Authority
- Normalized
- bryan county ambulance authority— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- FEDERALHHS OCR enforcementas victim2024-10-31
HHS OCR settled with Bryan County Ambulance Authority (BCAA) for $90,000 regarding a 2022 ransomware attack. BCAA failed to conduct a compliant risk analysis as required by the HIPAA Security Rule. The incident affected 14,273 patients. This was OCR's 7th ransomware enforcement action and the first under its Risk Analysis Initiative.
- Washington State AGas victim2022-05-24
Bryan County Ambulance Authority experienced a ransomware incident starting Nov 24, 2021. Files were encrypted and potentially exfiltrated between Nov 24-29, 2021. Data included names, SSNs, and medical info. One Washington resident was notified on May 18, 2022. Access was contained, data restored, and credit monitoring offered.
- Montana State AGas victim2022-05-18
Bryan County Ambulance Authority notified Montana residents of a November 24, 2021 ransomware incident. The attacker encrypted files and potentially exfiltrated personal information, including medical data. The Authority contained the threat, restored data, engaged forensic investigators, and offered IDX identity theft protection services to affected individuals.
- OKLAHOMAHHS OCRas victim2022-05-18
Bryan County Ambulance Authority (BCAA), an Oklahoma emergency medical services provider, reported to HHS OCR on 2022-05-18 a Hacking/IT Incident (ransomware attack) affecting 14,273 individuals. Ransomware encrypted files on BCAA's network server containing patient ePHI. OCR found BCAA failed to conduct a compliant risk analysis. BCAA agreed to a $90,000 settlement and a 3-year corrective action plan — the first enforcement action under OCR's Risk Analysis Initiative. No business associate was involved.
- Illinois State AGas victim2022-01-01
BRYAN COUNTY AMBULANCE AUTHORITY filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-340). The register records the breach as discovered on November 21, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.