The Department of Aging and Disability Services
bd_156dbd18482cb576 · schema v1 · pii pii-v1
Full breach record for The Department of Aging and Disability Services →The Texas Department of Aging and Disability Services (DADS) reported to HHS OCR on June 11, 2015 an Unauthorized Access/Disclosure breach affecting 6,600 individuals. An internal application was migrated from a private server to a public server; a software flaw allowed ePHI (names, addresses, SSNs, treatment information) to be accessed without credentials. OCR later imposed a $1.6M civil money penalty against successor entity TX HHSC for HIPAA Privacy and Security Rule violations from 2013–2017. Breached information located on Network Server.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 1, 2013
Begins
Jun 11, 2015
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.