DisclosureLens
PhysicalHealthcareHealthcareTheftCustomer Data InvolvedPHIHealth (basic)Identity (basic)LowContained

American Sleep Medicine

bd_2d67eb1294a3dc28 · schema v1 · pii pii-v1

Severity

Low

Discovered

Mar 3, 2015

Filed

Apr 16, 2015

To disclose

6 weeks

Affected

Not disclosed

Linked

2 filings

Confidence

66%
Full breach record for American Sleep Medicine

American Sleep Medicine reported the theft of an external hard drive from a locked server room in San Diego, discovered on March 3, 2015. The drive contained patient information from 2012 sleep studies, including names, dates of birth, medical history, and sleep study results. No SSNs or financial data were involved. The company reported the theft to police and offered 90 days of credit monitoring.

California clockDiscovered Mar 3, 2015Notified Apr 15, 201543d CA 60-day OK6 weeks discovery → filing

Incident timeline

discovery → filing · 6 weeks / 44 days

Mar 3, 2015

Begins

Mar 3, 2015

Discovered

Apr 16, 2015

Filed

vs. sector median

6 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings

View merged incident ↗
HHS OCRApr 16 · first
California State AGApr 16 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.