Centura Health
bd_2f039d28eef85361 · schema v1 · pii pii-v1
Full breach record for Centura Health →Centura Health (Colorado Healthcare Provider) reported to HHS OCR on 2014-04-22 a Hacking/IT Incident affecting 12,286 individuals. Employees inadvertently responded to a phishing email by clicking a fraudulent link and surrendering their usernames and passwords, enabling attacker access to those email accounts. Breached ePHI included demographic (names, addresses, DOB, phone numbers, SSNs), clinical (diagnoses, lab results, medications), and financial (claims) information. The CE notified HHS, affected individuals, media, and the FBI, and offered free credit monitoring. Corrective actions included updated risk management, employee retraining, and enhanced phishing-awareness education. OCR confirmed corrective action implementation.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Apr 22, 2014
- Raw hash
- 43bd44ddb1bfda986127f85e678843fee855691109f11a07ba38a7239ba19cfe
Source filing
Reporting entity
- Name
- Centura Healthnorm: centura health
- Industry
- Health Care Services
Victim entity
- Name
- Centura Healthnorm: centura health
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 12,286
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566 PhishingT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- OCR initiated investigationCE notified HHSCE notified Federal Bureau of InvestigationOCR obtained assurance of corrective action implementation
- Initial access
- phishing_link
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.