Centura Health
bd_2f039d28eef85361 · schema v1 · pii pii-v1
Full breach record for Centura Health →3 incidents on fileCentura Health (Colorado Healthcare Provider) reported to HHS OCR on 2014-04-22 a Hacking/IT Incident affecting 12,286 individuals. Employees inadvertently responded to a phishing email by clicking a fraudulent link and surrendering their usernames and passwords, enabling attacker access to those email accounts. Breached ePHI included demographic (names, addresses, DOB, phone numbers, SSNs), clinical (diagnoses, lab results, medications), and financial (claims) information. The CE notified HHS, affected individuals, media, and the FBI, and offered free credit monitoring. Corrective actions included updated risk management, employee retraining, and enhanced phishing-awareness education. OCR confirmed corrective action implementation.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Apr 22, 2014
Filed
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.