CALIFORNIAAccidentalHealthcareHealthcareMisdeliveryCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICLowContained
Orange County Global Medical Center
bd_00db99f48b2acbdf · schema v1 · pii pii-v1
Full breach record for Orange County Global Medical Center →Orange County Global Medical Center reported to HHS on 2017-03-02 a Unauthorized Access/Disclosure affecting 677 individuals. Breached information located on Email. A workforce member inadvertently sent medical statistical reports containing PHI (treatment, diagnostic info, MRNs, DOBs) to an unauthorized recipient. The CE requested deletion, notified HHS/individuals/media, and is completing an enterprise-wide security risk analysis.
HIPAA clock✓ HHS notified22 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_dba17c04c3f9614eCalifornia State AGfiled 2017-03-02Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 2, 2017
- Raw hash
- a477d54ce9a1f3a6cb30f24a038bdd94abe501b9b2e942064a6a88b6e2608092
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Orange County Global Medical Centernorm: orange county global medical center
- Industry
- Health Care Services
Victim entity
- Name
- Orange County Global Medical Centernorm: orange county global medical center
- Industry
- Healthcaresource default
Incident
- Discovered
- Feb 8, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 677
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1530 Data from Cloud Storage Object
- Threat actor
- Internal
Compliance
- Time to disclose
- 22 days(22 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Feb 8, 2017→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.