Dynasplint Systems
Disclosed Aug 6, 20206 years ago102,800 affectedConfirmed
Dynasplint Systems, the covered entity (CE), reported that multiple employees were the victims of an email phishing attack that affected the protected health information (PHI) of 102,800 individuals. The PHI involved included names, Social Security numbers, addresses, drivers’ license numbers, dates of birth, lab results, medications prescribed, and financial and other treatment information. The CE notified HHS, affected individual, the media, and provided complimentary credit monitoring services. In response to the breach, the CE implemented additional administrative and technical safeguards to better protect its PHI.
What is known
| People affected | 102,800 (as reported by the organization) |
|---|---|
| Disclosed | Aug 6, 2020 |
| Discovered | May 16, 2020 |
| Happened | Apr 29, 2020 |
| Attack | Ransomware |
| Data exposed | Names, Social Security numbers, Health |
| Sector | Tech · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Dynasplint Systemsoag.ca.gov · Official notice | Official notice |
| Washington Attorney General breach notice: Dynasplint Systemsatg.wa.gov · Official notice | Official notice |
| Oregon DOJ breach notice: Dynasplint Systemsjustice.oregon.gov · Official notice | Official notice |
| Indiana Attorney General 2020 data breach report: Dynasplint Systemsin.gov · Official notice | Official notice |
| Maine Attorney General breach notice archive: Dynasplint Systemsmaine.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Dynasplint Systems (Healthcare Provider, MD)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Aug 6, 2020 | 102,800 |
| Indiana AGresidents of IN | Aug 7, 2020 | 1,345 |
| Maine AGresidents of ME | Aug 7, 2020 | 102,800 |
| Washington AGresidents of WA | Aug 10, 2020 | 1,364 |
| California AGresidents of CA | Aug 17, 2020 | |
| Oregon DOJresidents of OR | Aug 17, 2020 | 102,800 |
History of this record
- 2026-09-25 · data_types: ["names","ssn"] to ["names","ssn","health"] · backfill source
- 2026-09-25 · disclosed: 2020-08-07 to 2020-08-06 · backfill source
- 2026-09-25 · summary: empty to Dynasplint Systems, the covered entity (CE), reported that multiple employees were the victims of an email phishing attack that affected the protected health information (PHI) of 102,800 individuals. The PHI involved included names, Social · backfill source
- 2026-09-25 · data_types: [] to ["names","ssn"] · backfill source
- 2026-09-25 · records_basis: empty to organization · backfill source
- 2026-09-25 · records: empty to 102800 · backfill source
- 2026-09-25 · disclosed: 2020-08-10 to 2020-08-07 · backfill source
- 2026-09-25 · attack: unknown to ransomware · backfill source
- 2026-09-25 · disclosed: 2020-08-17 to 2020-08-10 · backfill source
- 2026-09-25 · discovered: empty to 2020-05-16 · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.