Meritus Medical Center, Inc.
bd_226edd21b9fda910 · schema v1 · pii pii-v1
Full breach record for Meritus Medical Center, Inc. →Meritus Medical Center, Inc. (MD) reported to HHS OCR on 2015-06-26 an Unauthorized Access/Disclosure affecting 1,029 individuals. An audit revealed that a Walgreens pharmacy vendor employee accessed patient PHI in the electronic health record (EHR) without a business need. PHI exposed included names, dates of birth, medical record numbers, health insurance information, Medicare ID numbers, and clinical information. The CE terminated the employee's access, escorted them from campus, notified HHS, media, and affected individuals, offered credit monitoring, and implemented new technical controls limiting vendor EHR access. OCR obtained corrective action assurances.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Jun 26, 2015
Filed
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.