Doctors' Management Service, Inc
ent_8e187a888012a7a9e6bd1f4e
Disclosures
7
HHS OCR enforcement · State AG · HHS OCR · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
206,695
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Doctors' Management Service, Inc
- Normalized
- doctors management service— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- doctorsmanagementservice.org
Disclosure history (7)newest first
- FEDERALHHS OCR enforcementas victim2023-10-31
HHS OCR settled a ransomware investigation with Doctors’ Management Services, Inc. (DMS), a business associate, for $100,000. DMS failed to conduct a risk analysis, review audit logs, and implement appropriate security policies after its network was infected with GandCrab ransomware, impacting approximately 206,695 individuals.
- New Hampshire State AGas victim2019-05-28
Doctors' Management Service, Inc. notified the NH AG of a ransomware incident involving GandCrab malware. Initial access occurred via RDP on April 1, 2017, but was not discovered until December 24, 2018. Five NH residents (doctors) were impacted, with credentialing info (SSN, name, address) and potential PHI exposed. Data was encrypted but restored from backups; no ransom paid. Identity theft protection offered.
- Oregon State AGas victim2019-04-24
Doctors' Management Service, Inc. ("DMS") reported a data breach to the Oregon Attorney General. The breach was reported on 2019-04-24. The breach occurred during 4/1/2017 - 12/24/2018. The breach was discovered on 12/24/2018. 206,695 individuals were affected. Notice was sent on 4/22/2019.
- Massachusetts State AGas victim2019-04-23
Doctors' Management Services, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-04-23. 39,201 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2019-04-22
Doctors’ Management Service, Inc. (DMS) disclosed a ransomware incident involving the GandCrab variant. Initial unauthorized access occurred on April 1, 2017 via RDP; technical issues were first noticed on December 24, 2018. The incident impacted personal health information (PHI) including names, SSNs, DOBs, driver's licenses, and medical data. No evidence of data exfiltration was found, but activity could not be ruled out. DMS restored data from backups, engaged forensic investigators, notified law enforcement and HHS, and offered credit monitoring.
- MASSACHUSETTSHHS OCRas victim2019-04-22
Doctors Management Services, Inc. reported to HHS on 2019-04-22 a Hacking/IT Incident affecting 206,695 individuals. Breached information located on Network Server. The incident involved GandCrab ransomware encrypting files and exfiltrating data. Initial access occurred 2017-04-01; detected 2018-12-24. $100,000 settlement reached with OCR.
- Illinois State AGas victim2019-01-01
DOCTORS' MGMT SERVICE INC. filed a data-breach notice with the Illinois Attorney General during 2019 (case 2019-186). The register records the breach as discovered on February 15, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.