NCPhysicalHealthcareHealthcareLossCustomer Data InvolvedHEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNTLowResolved
Haywood County NC
bd_08431994499b535e · schema v1 · pii pii-v1
Full breach record for Haywood County NC →Haywood County NC (a Healthcare Provider in NC) reported to HHS on 2015-02-09 a Loss affecting 955 individuals. On or around October 31, 2014, a paper accounts receivable report went missing from the CE's billing office. The report contained patients' internal IDs, names, clinics visited, and amounts owed. The CE notified affected individuals and media, contacted law enforcement, enhanced physical security, added locked file cabinets, restricted office access, retrained staff, and reviewed HIPAA policies. OCR reviewed policies and training documentation.
HIPAA clock✓ HHS notified14 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed955 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Feb 9, 2015
- Raw hash
- 755bf5eed5c0adb60e7fe16765c855c0ffc4c168a0aa8b83138d166308a0c528
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Haywood County NCnorm: haywood county nc
- Industry
- Health Care Services
Victim entity
- Name
- Haywood County NCnorm: haywood county nc
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Oct 31, 2014
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 955
- Data types
- HEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- Regulator citations
- OCR obtained and reviewed CE's relevant HIPAA policies and procedures and documentation of staff training
Compliance
- Time to disclose
- 14 weeks(101 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Oct 31, 2014→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.