Highlands Cashier Hospital
bd_19882848e7b76d9b · schema v1 · pii pii-v1
Full breach record for Highlands Cashier Hospital →Highlands Cashier Hospital reported to HHS on 2014-12-11 a breach involving unauthorized access or disclosure that affected 26,115 individuals. A business associate, Computer Programs and Systems, Inc., incorrectly configured the hospital's firewall, which exposed patient data on the internet. The exposed information, located on a network server, included patient names, addresses, dates of birth, treatment details, and, for 21,072 individuals, Social Security numbers. In response, the hospital implemented enhanced firewall safeguards, started monitoring web traffic, and began conducting external vulnerability scans.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Dec 11, 2014
- Raw hash
- 419db9df61cff40d244688f3de98b5046c6314955d806e16c4832c0e308835f0
Source filing
Reporting entity
- Name
- Highlands Cashier Hospitalnorm: highlands cashier hospital
- Industry
- Health Care Services
Victim entity
- Name
- Highlands Cashier Hospitalnorm: highlands cashier hospital
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 26,115
- Data types
- IDENTITY_BASICHEALTH_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- Threat actor
- Partner
- Third party
- via Computer Programs and Systems, Inc.
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.