FEDERALPhysicalHealthcareFinancial ServicesHealthcareTheftCustomer Data InvolvedHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTMediumResolved
Health Care Service Corporation Stable Value Fund
bd_06296347c67e18bf · schema v1 · pii pii-v1
Full breach record for Health Care Service Corporation Stable Value Fund →Health Care Service Corporation (IL, Health Plan) reported to HHS OCR on 2012-10-26 a Theft affecting 501 individuals. On July 28, 2011, paper documents containing PHI were stolen from an employee's locked car parked at their home. Documents included names, member IDs, birthdates, group numbers/names, and diagnostic information for ~511 individuals (498 in TX, 13 in NM). The CE counseled the responsible employee, revised PHI safeguard policies, and notified all staff via email. OCR confirmed corrective actions were implemented.
HIPAA clock✓ HHS notified15 months discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed501 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Oct 26, 2012
- Raw hash
- a19fecc08f994adad1fc28362f9f87e673f5841073f8978d4fe99100459ff6ef
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Health Care Service Corporation Stable Value Fundnorm: health care service corporation stable value
- Domain
- hcsc.com
- Industry
- Insurance — Health
Victim entity
- Name
- Health Care Service Corporation Stable Value Fundnorm: health care service corporation stable value
- Domain
- hcsc.com
- Industry
- Insurance — Health
- Industry
- Healthcaresource defaultFinancial Servicesllm
Incident
- Discovered
- Jul 28, 2011
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 501
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- External
- Regulator citations
- OCR obtained documentation evidencing that the CE implemented the corrective actions listed.
Compliance
- Time to disclose
- 15 months(456 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jul 28, 2011→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.