AMEDISYS, INC.
bd_131827e29580fc23 · schema v1 · pii pii-v1
Full breach record for AMEDISYS, INC. →On February 23, 2015, Amedisys, Inc. (LA) discovered that 142 encrypted computers and laptops were unaccounted for, accessible to former employees who had left or been terminated between January 1, 2011 and December 31, 2014. The devices contained ePHI of approximately 6,909 individuals, including names, dates of birth, addresses, SSNs, diagnoses, lab results, medications, treatment info, and claims. Breach notification was sent to HHS, individuals, and media. Remediation included enhanced termination/device recovery policies and an offline device freeze capability. Breached information located on Desktop Computer, Electronic Medical Record, and Laptop.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 1, 2015
- Raw hash
- c401d1cf9d70f10bcfbfcbaa4c6e6972326342f203b246c2c043943c99452f38
Source filing
Reporting entity
- Name
- AMEDISYS, INC.norm: amedisys
- Domain
- amedisys.com
- Industry
- Health Care Services
Victim entity
- Name
- AMEDISYS, INC.norm: amedisys
- Domain
- amedisys.com
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Feb 23, 2015
- Materiality determined
- —
- Notification sent
- Mar 1, 2015
- Affected individuals
- 6,909
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical MediumT1078 Valid Accounts
- Threat actor
- Internal
- Regulator citations
- HHS OCR provided technical assistance regarding conducting a risk analysis and requirements to identify and assess potential risks and vulnerabilities of ePHI.CE hired a third-party vendor to conduct a complete enterprise-wide risk analysis to be provided to OCR upon completion.
- Initial access
- insider_action
Compliance
- Time to disclose
- 6 days(6 days from discovery to filing)
- Compliance flags
- HIPAA 60-day OK · 6dHHS notified · 6d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Feb 23, 2015→ Notified: Mar 1, 20156d 60 days HIPAA 60-day OK HIPAA Discovered: Feb 23, 2015→ Notified: Mar 1, 20156d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.