THE CARLE FOUNDATION
bd_0e9a9f8e6e3b6dfd · schema v1 · pii pii-v1
Full breach record for THE CARLE FOUNDATION →On June 14, 2016, Carle Foundation Hospital (The Carle Foundation) discovered that its business associate, The Claro Group, placed PHI-containing files on a public FTP server on February 17, 2016, potentially making them viewable via the internet. The breach affected 1,185 individuals and involved demographic, clinical, and account number information. The CE notified HHS, affected individuals, and media. Remediation included disabling the FTP account, individual account migration, and controls including 2FA and DLP tools. OCR obtained documented assurances of corrective actions.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Aug 4, 2016
- Raw hash
- 840e35eaeb430227ba6b77d71f334250a2936da0438e38aac63021625a31b6b5
Source filing
Reporting entity
- Name
- THE CARLE FOUNDATIONnorm: the carle
- Industry
- Health Care Services
Victim entity
- Name
- THE CARLE FOUNDATIONnorm: the carle
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Jun 14, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,185
- Data types
- HEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access· The Claro Group
- Threat actor
- Partner
- Regulator citations
- HHS OCR breach notification submitted; OCR obtained documented assurances of corrective action
- Third party
- via The Claro Group
Compliance
- Time to disclose
- 7 weeks(51 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jun 14, 2016→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.