Bi-Bett Corporation
bd_0507b9d44f701bcc · schema v1 · pii pii-v1
Full breach record for Bi-Bett Corporation →Bi-Bett Corporation, a Business Associate based in CA, reported to HHS on 2023-07-25 a Hacking/IT Incident affecting 4,639 individuals. An employee was the target of an email phishing attack that exposed PHI including names, addresses, dates of birth, driver's license numbers, Social Security numbers, and health insurance information. Breached information was located on Email. The BA notified HHS, affected individuals, the media, and provided substitute notice. Free credit monitoring was offered and additional administrative, technical, and security safeguards were implemented. OCR provided technical assistance regarding HIPAA Rules.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_1810ca3e6070f679California State AGfiled 2023-07-25Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jul 25, 2023
- Raw hash
- 7f53022fd5b63cab48fa537608148e7c3cddc68d6882202410e32e93d3f145e1
Source filing
Reporting entity
- Name
- Bi-Bett Corporationnorm: bi bett
- Industry
- Business Associate
Victim entity
- Name
- Bi-Bett Corporationnorm: bi bett
- Industry
- Business Associate
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 4,639
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566 Phishing
- Threat actor
- External
- Regulator citations
- OCR provided technical assistance regarding the HIPAA Rules
- Initial access
- phishing_link
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.