DisclosureLens
NORTH DAKOTAPhysicalHealthcareHealthcareTheftCustomer Data InvolvedHealth (basic)Identity (basic)LowResolved

Medcenter One

bd_1f1715c08a210185 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Nov 17, 2011

To disclose

Affected

650

Confidence

98%
Full breach record for Medcenter One

On or about October 21, 2011, MedCenter One, Inc. (ND) failed to safeguard the ePHI of approximately 650 patients when an unencrypted, password-protected laptop and a bag containing 11 patient charge tickets were stolen from an employee's vehicle. ePHI involved included demographic information. The CE notified HHS, affected individuals, and the media. Corrective actions included encrypting all laptops, new IT security policies, staff retraining, and employee sanction. OCR obtained assurances of implementation. MedCenter One later merged with Sanford Health on July 3, 2012. Breached information located on Laptop.

HIPAA clock HHS notified
no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.

Incident timeline

Oct 21, 2011

Begins

Nov 17, 2011

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed650 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.