Serene Sedation
bd_24e19da63db15456 · schema v1 · pii pii-v1
Full breach record for Serene Sedation →An unauthorized user accessed the computer network of a business associate (BA) which stored the financial records of Serene Sedation, LLC (CE). The server contained the protected health information (PHI) of approximately 5,207 individuals, including demographic and financial information. Following the breach, the CE discontinued storing financial records on its BA's networks, and increased its own security by adding encryption. OCR reviewed the CE’s risk analysis and BA agreements and obtained assurances that the CE took immediate steps to increase the security of ePHI by encrypting its computer hard drives, encrypting outgoing e-mails, and using a virtual private network (VPN). The CE provided breach notification to HHS, affected individuals, and the media.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 14, 2018
- Raw hash
- 873d1dd6a9664710bdcc12a683288c0459778eb70500f072286db83d1e9f925c
Source filing
Reporting entity
- Name
- Serene Sedationnorm: serene sedation
- Industry
- Health Care Services
Victim entity
- Name
- Serene Sedationnorm: serene sedation
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 5,207
- Data types
- HEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- Regulator citations
- OCR reviewed the CE’s risk analysis and BA agreements.OCR obtained assurances that the CE took immediate steps to increase the security of ePHI.
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.