Advanced ENT Head & Neck Surgery
bd_11425d672160c000 · schema v1 · pii pii-v1
Full breach record for Advanced ENT Head & Neck Surgery →A workforce member of Advanced ENT Head & Neck Surgery (CA) surreptitiously photographed patients, recorded conversations, copied legal ID and payment records, stole multiple mobile devices containing ePHI, and posted breached information to a social media account. The breach, discovered ~May 1, 2017, affected ~15,000 individuals. PHI involved clinical, demographic, and financial information across desktop computers, EMRs, email, laptops, portable devices, and paper/films. The CE terminated the employee, notified HHS and other enforcement agencies, and implemented encryption, password, and physical security improvements. OCR closed its investigation after the DOJ accepted the case.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 31, 2017
- Raw hash
- 6e30327c3a65044c1c2139439eaec9fe274fbf9ba15afd5924326b11328f32c5
Source filing
Reporting entity
- Name
- Advanced ENT Head & Neck Surgerynorm: advanced ent head neck surgery
- Industry
- Health Care Services
Victim entity
- Name
- Advanced ENT Head & Neck Surgerynorm: advanced ent head neck surgery
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- May 1, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 15,000
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical MediumT1078 Valid Accounts
- Threat actor
- Internal
- Regulator citations
- HHS OCR notification submittedCase referred to / accepted by Department of JusticeOCR investigation closed — DOJ accepted
- Initial access
- insider_action
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: May 1, 2017→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.