GRM Information Management Services
bd_28d26c271e322cd7 · schema v1 · pii pii-v1
Full breach record for GRM Information Management Services →Unencrypted clinical system backup tapes containing ePHI of 1,700,000 individuals were stolen from an unlocked vehicle belonging to an employee of GRM Information Management Services, a business associate of the covered entity. ePHI included names, MRNs, SSNs, addresses, phone numbers, health plan numbers, dates of birth/admission/treatment/discharge/death, mother's name, next of kin, and clinical information (diagnoses, treatment, prognosis, lab results, medications). The covered entity filed a police report, notified HHS, media, and affected individuals, terminated the BA agreement, and installed encryption software on backup media following OCR's investigation. Incident occurred prior to the September 23, 2013 HIPAA Omnibus compliance date.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Feb 11, 2011
- Raw hash
- 1b0622878af9128e0a15cd682770837b9e45613c56ef4f504e3d2975ba101f42
Source filing
Reporting entity
- Name
- GRM Information Management Servicesnorm: grm information management
- Industry
- Business Associate
Victim entity
- Name
- GRM Information Management Servicesnorm: grm information management
- Industry
- Business Associate
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,700,000
- Data types
- PHIPIIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- Threat actor
- External
- Regulator citations
- HHS OCR breach report submitted 2011-02-11OCR investigation completed; CE found to have proper BA agreement in place
- Third party
- via GRM Information Management Services
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.