Serene Sedation
bd_24e19da63db15456 · schema v1 · pii pii-v1
Full breach record for Serene Sedation →An unauthorized user accessed the computer network of a business associate (BA) which stored the financial records of Serene Sedation, LLC (CE). The server contained the protected health information (PHI) of approximately 5,207 individuals, including demographic and financial information. Following the breach, the CE discontinued storing financial records on its BA's networks, and increased its own security by adding encryption. OCR reviewed the CE’s risk analysis and BA agreements and obtained assurances that the CE took immediate steps to increase the security of ePHI by encrypting its computer hard drives, encrypting outgoing e-mails, and using a virtual private network (VPN). The CE provided breach notification to HHS, affected individuals, and the media.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Mar 14, 2018
Filed
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.