The Children's Hospital of Philadelphia
bd_06532e5c8b532034 · schema v1 · pii pii-v1
Full breach record for The Children's Hospital of Philadelphia →The Children's Hospital of Philadelphia (CHOP) reported to HHS on 2018-10-23 a Hacking/IT Incident affecting 5,368 individuals. On August 23, 2019, a phishing email sent to 679 Outlook users enabled an unauthorized actor to access a physician's email account and the accounts of five employees who forwarded work email externally. The compromised account contained PHI including demographic and clinical information of approximately 5,368 patients. CHOP responded by disabling the account, recalling phishing emails, blocking the phishing site, resetting credentials, notifying affected individuals, and offering credit monitoring. Staff phishing training and a risk assessment update followed. OCR obtained documented assurances of corrective action.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Oct 23, 2018
- Raw hash
- ad06628c49f23606a6b9f15f0c7ba1d1f3fbd9924c757e7a3d15978687517697
Source filing
Reporting entity
- Name
- The Children's Hospital of Philadelphianorm: the children s hospital of philadelphia
- Domain
- chop.edu
- Industry
- Health Care Services
Victim entity
- Name
- The Children's Hospital of Philadelphianorm: the children s hospital of philadelphia
- Domain
- chop.edu
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 5,368
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566 PhishingT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- HHS OCR breach notification submitted; OCR obtained documented assurances of corrective action implementation
- Initial access
- phishing_link
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.