Pacific Ocean Pediatrics
bd_0e591f3801e66e30 · schema v1 · pii pii-v1
Full breach record for Pacific Ocean Pediatrics →Pacific Ocean Pediatrics (CA) reported to HHS OCR on 2017-05-15 a Theft affecting 18,637 individuals — patients and parents of patients. Three computers and two external hard drives were stolen from the office after a cleaning crew member left an exterior door unlocked. Breached PHI included names, addresses, dates of birth, phone numbers, sex, insurance information, and complete medical histories (symptoms, tests, diagnoses, prescriptions) of pediatric patients. The CE notified law enforcement, HHS, affected individuals, and the media, and subsequently improved physical security, installed a firewall, encrypted PHI-storing devices, and revised policies and procedures.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 15, 2017
- Raw hash
- cde372c97a23aec6aaf16321a50787d60c7ac33ce1e6002170e5c7544a79d190
Source filing
Reporting entity
- Name
- Pacific Ocean Pediatricsnorm: pacific ocean pediatrics
- Industry
- Health Care Services
Victim entity
- Name
- Pacific Ocean Pediatricsnorm: pacific ocean pediatrics
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 18,637
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTMINOR
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- External
- Regulator citations
- Reported to HHS OCROCR obtained assurances of corrective action implementationOCR provided technical assistance on Security Rule risk analysis and risk management provisions
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.