CALIFORNIAMisuseHealthcareHealthcarePrivilege AbuseCustomer Data InvolvedPHIHEALTH_BASICMediumResolved
Consolidated Tribal Health Project, Inc.
bd_0b7f65e4684593d8 · schema v1 · pii pii-v1
Full breach record for Consolidated Tribal Health Project, Inc. →Consolidated Tribal Health Project, Inc. reported to HHS on 2015-04-28 a Unauthorized Access/Disclosure affecting 4885 individuals. Breached information located on Desktop Computer, Electronic Medical Record, Email, Laptop, Network Server, Other Portable Electronic Device. An employee impermissibly accessed PHI prior to termination on 2014-10-31. No PHI was ultimately compromised.
HIPAA clockDiscovered Oct 31, 2014 → Notified Apr 28, 2015179d ✗ HIPAA 60-day late26 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed4,885 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Apr 28, 2015
- Raw hash
- 0f055b47ea66b988dbf44b0ec84672926771ec0811dd791e6445476e933cba17
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Consolidated Tribal Health Project, Inc.norm: consolidated tribal health project
- Industry
- Health Care Services
Victim entity
- Name
- Consolidated Tribal Health Project, Inc.norm: consolidated tribal health project
- Industry
- Healthcaresource default
Incident
- Discovered
- Oct 31, 2014
- Materiality determined
- —
- Notification sent
- Apr 28, 2015
- Affected individuals
- 4,885
- Data types
- PHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- Internal
- Initial access
- insider_action
Compliance
- Time to disclose
- 26 weeks(179 days from discovery to filing)
- Compliance flags
- HIPAA 60-day late · 179dHHS notified · 179d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Oct 31, 2014→ Notified: Apr 28, 2015179d 60 days HIPAA 60-day late HIPAA Discovered: Oct 31, 2014→ Notified: Apr 28, 2015179d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.