FEDERALAccidentalHealthcareHealthcareMisconfigurationBusiness Associate (HIPAA)Customer Data InvolvedHEALTH_BASICIDENTITY_BASICMediumResolved
Missouri Dept. of Mental Health
bd_1bd3a4ab871189d6 · schema v1 · pii pii-v1
Full breach record for Missouri Dept. of Mental Health →The Missouri Department of Mental Health reported that a former contractor of its business associate placed private client data in an unsecured cloud storage portal. The breach occurred between March 17, 2018, and August 31, 2018, affecting approximately 9,000 individuals. In response, the department confirmed the data was removed from the portal and obtained written verification that the data was destroyed or returned. The Office for Civil Rights (OCR) provided technical assistance to the department regarding security risk analysis and management.
HIPAA clock✓ HHS notified
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed9,000 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Oct 24, 2018
- Raw hash
- aec999fe0f5a37229a849058171e8594232dcd280619cefbcc43933fd73f3de2
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Missouri Dept. of Mental Healthnorm: missouri dept of mental health
- Industry
- Health Care Services
Victim entity
- Name
- Missouri Dept. of Mental Healthnorm: missouri dept of mental health
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 9,000
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- Threat actor
- Partner
- Regulator citations
- OCR provided the CE with technical assistance regarding the risk analysis and risk management provisions of the Security Rule.
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.