Ladies First Choice, Inc.
bd_1010c468c3499437 · schema v1 · pii pii-v1
Full breach record for Ladies First Choice, Inc. →In January 2014, Ladies First Choice, Inc. (FL) discovered that a former employee took and misappropriated a confidential computer program containing ePHI of 2,365 individuals. The data included names, dates of birth, Social Security numbers, addresses, and identifying codes, stored on a laptop/computer program. The CE notified HHS, affected individuals, and the media. Corrective actions included staff retraining, policy review, new risk analysis, encryption, secure backup, and a civil action against the former employee. OCR obtained assurances of corrective action. Reported to HHS on 2014-04-23.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Apr 23, 2014
- Raw hash
- 4e5f042fef70fe9f7943fcb3d5d2078e1b95617e595ce4aa6e144e98d99db719
Source filing
Reporting entity
- Name
- Ladies First Choice, Inc.norm: ladies first choice
- Industry
- Health Care Services
Victim entity
- Name
- Ladies First Choice, Inc.norm: ladies first choice
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Jan 1, 2014
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 2,365
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical MediumT1078 Valid Accounts
- Threat actor
- Internal
- Regulator citations
- HHS OCR investigation; OCR obtained assurances of corrective action implementation
- Initial access
- insider_action
Compliance
- Time to disclose
- 16 weeks(112 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jan 1, 2014→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.