Valley View Hospital Association
bd_191aba10d5719206 · schema v1 · pii pii-v1
Full breach record for Valley View Hospital Association →On January 25, 2014, Valley View Hospital Association (Glenwood Springs, CO) discovered malware had infected 172 computer workstations. On 90 of those workstations, the malware captured screen shots of ePHI belonging to 5,415 individuals and stored them as encrypted hidden files. Exposed data included names, SSNs, demographic information, and credit card data. The CE deployed anti-virus software, notified HHS, affected individuals, and media. OCR's investigation led to revised ePHI safeguarding procedures and an updated risk analysis and management plan. Breached information located on Desktop Computer and Laptop.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 14, 2014
- Raw hash
- fc4b63bc0e70ecb6634102dfbcdd7c91679a91eea700edfa0a09c11012f889ea
Source filing
Reporting entity
- Name
- Valley View Hospital Associationnorm: valley view hospital
- Industry
- Health Care Services
Victim entity
- Name
- Valley View Hospital Associationnorm: valley view hospital
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Jan 25, 2014
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 5,415
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1113 Screen CaptureT1027 Obfuscated Files or InformationT1005 Data from Local System
- Threat actor
- ExternalFinancial
- Regulator citations
- OCR investigated and obtained assurance to update risk analysis and risk management planOCR provided technical assistance on Security Rule risk analysis and risk management requirementsCE revised procedures for safeguarding ePHI and protecting against malicious software
Compliance
- Time to disclose
- 7 weeks(48 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jan 25, 2014→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.