Henry Ford Health System
bd_1bf520d3d395b009 · schema v1 · pii pii-v1
Full breach record for Henry Ford Health System →Henry Ford Health System (MI) reported to HHS OCR on 2015-01-09 a Loss breach affecting 2,336 individuals. On October 23, 2014, a physician lost a personal (non-employer-issued) USB flash drive containing PHI — clinical and demographic information — in violation of CE policy requiring employer-issued encrypted flash drives. The CE sanctioned the employee, notified affected individuals and media, and provided OCR with written assurances of corrective actions including an enhanced asset management program and enterprise data mapping. Breached information was located on a portable electronic device.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jan 9, 2015
- Raw hash
- d0f288f89814985987e361bc38c78593a99ddb641a8098ff7b9828e8e7cae93b
Source filing
Reporting entity
- Name
- Henry Ford Health Systemnorm: henry ford health system
- Domain
- henryford.com
- Industry
- Health Care Services
Victim entity
- Name
- Henry Ford Health Systemnorm: henry ford health system
- Domain
- henryford.com
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Oct 23, 2014
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 2,336
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- Internal
- Regulator citations
- HHS OCR investigation consolidated with existing CE investigationOCR provided technical assistance on Security Rule Risk Analysis requirementsOCR obtained documented assurances of corrective action implementation
Compliance
- Time to disclose
- 11 weeks(78 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Oct 23, 2014→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.