CALIFORNIAMisuseHealthcareHealthcarePrivilege AbuseBusiness Associate (HIPAA)Customer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICMediumResolved
Muir Medical Group, IPA. Inc.
bd_2d64b798aa7d5d45 · schema v1 · pii pii-v1
Full breach record for Muir Medical Group, IPA. Inc. →Muir Medical Group, IPA, Inc. reported to HHS on 2018-05-22 a Unauthorized Access/Disclosure affecting 5485 individuals. Breached information located on Network Server. An employee impermissibly accessed and copied client electronic data, including demographic, insurance, and clinical PHI. The BA notified HHS, patients, and media, offered identity theft protection, contacted law enforcement, engaged a digital forensics firm, and retrained staff.
HIPAA clock✓ HHS notified11 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_6a3fc94325935086California State AGfiled 2018-05-22Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 22, 2018
- Raw hash
- 0203bf3179d497a053edf7b295460844210d3e217206a6cb7907882895ddd984
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Muir Medical Group, IPA. Inc.norm: muir medical group ipa
- Industry
- Health Care Services
Victim entity
- Name
- Muir Medical Group, IPA. Inc.norm: muir medical group ipa
- Industry
- Healthcaresource default
Incident
- Discovered
- Mar 7, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 5,485
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- Internal
- Third party
- via Muir Medical Group, IPA, Inc.business associate
- Initial access
- insider_action
Compliance
- Time to disclose
- 11 weeks(76 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Mar 7, 2018→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.