AZHackingHealthcareHealthcareVulnerability ExploitBusiness Associate (HIPAA)Customer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICHighResolved
The Biomechanics LLC
bd_17426b06290e458f · schema v1 · pii pii-v1
Full breach record for The Biomechanics LLC →The Biomechanics LLC (AZ, Healthcare Provider) reported to HHS on 2016-11-16 a Hacking/IT Incident affecting 1,049 individuals. A security researcher accessed ePHI due to a vulnerability in a business associate's data storage system; the researcher did not intend to use or disclose the information. Breached data included names, addresses, birthdates, driver's license numbers, SSNs, diagnoses, lab results, and medications. The BA returned the ePHI and later closed its business. OCR investigated and the CE increased BA oversight awareness.
HIPAA clock✓ HHS notified
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,049 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Nov 16, 2016
- Raw hash
- 3569c0be63fc11ddf069337b4d61d277b9f960a798ee9d8f5346ac3fa9cddbde
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- The Biomechanics LLCnorm: the biomechanics
- Industry
- Health Care Services
Victim entity
- Name
- The Biomechanics LLCnorm: the biomechanics
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,049
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- OCR investigation opened; CE provided BA agreement to OCR; CE increased awareness of BA oversight responsibilities
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.