Aventura Hospital and Medical Center
bd_25470069f8020894 · schema v1 · pii pii-v1
Full breach record for Aventura Hospital and Medical Center →Aventura Hospital and Medical Center (FL) reported to HHS on 2014-09-11 a Theft/Unauthorized Access breach affecting 82,601 individuals. On or around May 28, 2014, an employee of Valesco Ventures — a contractor providing staffing and ancillary services — inappropriately accessed the PHI of approximately 82,601 patients, including demographic information, via the hospital's network server. The CE notified HHS, affected individuals, and the media, offered credit monitoring and identity theft protection, retrained staff, updated audit controls, tightened system access approvals, revised BA contracts, and completed a new risk analysis and risk management plan. OCR obtained assurances that all corrective actions were implemented.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Sep 11, 2014
- Raw hash
- 53f4818878cfeb1e48ff12db308a4e383182aae351965e9e34d974ee11867516
Source filing
Reporting entity
- Name
- Aventura Hospital and Medical Centernorm: aventura hospital and medical center
- Industry
- Health Care Services
Victim entity
- Name
- Aventura Hospital and Medical Centernorm: aventura hospital and medical center
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- May 28, 2014
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 82,601
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access· Valesco Ventures employee
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- Partner
- Regulator citations
- HHS OCR breach notification submittedOCR obtained assurances that corrective actions were implemented
- Third party
- via Valesco Venturescontractor staffing and ancillary services
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 15 weeks(106 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: May 28, 2014→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.