DisclosureLens
ILLINOISPhysicalHealthcareHealthcareTheftCustomer Data InvolvedHealth (basic)Identity (basic)LowResolved

Midwest Urological Group

bd_1e35c570ceb222e2 · schema v1 · pii pii-v1

Severity

Low

Discovered

May 30, 2014

Filed

Jul 30, 2014

To disclose

9 weeks

Affected

982

Confidence

98%
Full breach record for Midwest Urological Group

Midwest Urological Group (IL) reported to HHS on 2014-07-30 a Theft affecting 982 individuals. On May 30, 2014, an unencrypted laptop computer was stolen from a company closet. The laptop contained PHI including names and medical test data. The CE notified HHS, affected individuals, media, and police. Following the breach, the responsible employee was sanctioned and retrained, and new safeguard policies were implemented. OCR obtained written assurances of corrective action.

HIPAA clock HHS notified9 weeks discovery → filing
occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.

Incident timeline

discovery → filing · 9 weeks / 61 days

May 30, 2014

Begins

May 30, 2014

Discovered

Jul 30, 2014

Filed

vs. sector median

4 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed982 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.