
A 22-provider multi-specialty group with three clinics across the Denver metro.
Ransomware hit the network. Before the attackers encrypted anything, they copied patient records — names, dates of birth, diagnosis codes, partial SSNs — then locked scheduling, billing, and an EHR replica for three days. The moment the group confirmed a breach, two clocks started simultaneously: the federal HIPAA notification clock and Colorado's own 30-day clock under C.R.S. § 6-1-716. Colorado requires notification to affected residents within 30 days of determining a breach, and direct notice to the state Attorney General within that same 30 days if 500 or more Colorado residents are involved — one of the tightest deadlines in the country. There is an encryption safe harbor in the statute, but it didn't apply here: the attackers stole the records before encrypting anything, which is the standard ransomware play. Once data is out the door in the clear, the safe harbor is gone and the full notification obligation runs.
Cyber Extortion funded the ransom analysis — the group didn't pay, because its backups were clean and restorable. Data Breach Response paid for the forensics, the patient notifications, the AG correspondence, and credit monitoring. Because the theft happened before any encryption, the safe harbor never applied; the policy is what funded meeting the 30-day deadline from day one. We size your breach-response limit against your patient count and verify your backup architecture before binding.
The group hit the notification clock and kept the AG inquiry narrow. For a Colorado healthcare operation, the question isn't whether your data is encrypted — it's whether your policy funds a full breach response when exfiltration beats the encryption.













