Dr. Veronica Joann Barber
bd_285bc6ab5282de71 · schema v1 · pii pii-v1
Full breach record for Dr. Veronica Joann Barber →Dr. Veronica Joann Barber (VB), an optometrist working at the covered entity under a space-sharing agreement, copied the CE's entire patient database on December 15, 2013, and used the ePHI to solicit patients for her own practice. The breach affected 4,000 individuals. Exposed ePHI included names, SSNs, addresses, driver's licenses, dates of birth, credit card/bank account numbers, claims information, diagnoses, medications, and treatment information. The CE terminated the agreement, issued a cease-and-desist, notified HHS and individuals, installed firewalls, completed a risk assessment, and improved physical and logical access controls. Breached info located on Network Server.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jul 28, 2014
- Raw hash
- 191d471e531be407c41657dee2bc3a92ba9f0ec41b7b35a1fd33f56cef345f84
Source filing
Reporting entity
- Name
- Dr. Veronica Joann Barbernorm: dr veronica joann barber
Victim entity
- Name
- Dr. Veronica Joann Barbernorm: dr veronica joann barber
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 4,000
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access· Veronica Joann Barber, O.D.
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- PartnerFinancial
- Regulator citations
- HHS OCR technical assistance provided; CE completed risk assessment and notified media per OCR guidance
- Third party
- via Veronica Joann Barber, O.D.
- Initial access
- valid_credentials
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.