DisclosureLens
COLORADOAccidentalHealthcareGovernmentHealthcareMisdeliveryBusiness Associate (HIPAA)Customer Data InvolvedHealth (basic)Identity (basic)MediumResolved

Colorado Department of Health Care Policy and Financing

bd_09b41b2aec6b30a8 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Oct 10, 2014

To disclose

Affected

15,380

Confidence

98%
Full breach record for Colorado Department of Health Care Policy and Financing6 incidents on file

On July 30 and September 3, 2014, a business associate of Colorado Department of Health Care Policy & Financing mistakenly sent postcards to approximately 15,380 clients containing viewable PHI, including names, addresses, and references to each client's status as a public assistance client receiving behavioral health care services. Following the breach, the CE and BA ceased postcard communications, implemented new policies and procedures, and conducted privacy training. OCR obtained assurances of corrective action. Breach reported to HHS on 2014-10-10. Breached information located in: Other.

HIPAA clock HHS notified
no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.

Incident timeline

Jul 30, 2014

Begins

Oct 10, 2014

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed15,380 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.