DisclosureLens
MisuseHealthcareHealthcarePrivilege AbuseEmployee Data InvolvedTargetedPHIHealth (basic)Identity (basic)LowResolved

Asante Health System

bd_30312e388e01c288 · schema v1 · pii pii-v1

Severity

Low

Discovered

Oct 17, 2016

Filed

Dec 9, 2016

To disclose

8 weeks

Affected

1state residents only

Confidence

65%
Full breach record for Asante Health System2 incidents on file

Asante Health System notified patients that an employee inappropriately accessed electronic patient records between June 23, 2014, and October 22, 2016. The incident was discovered on October 17, 2016. Affected data included names, DOBs, medical record numbers, medications, diagnoses, and lab results. No SSNs or financial data were involved. The employee was disciplined per policy, and the organization enhanced workforce education and auditing.

Incident timeline

undetected · 847 days
discovery → filing · 8 weeks / 53 days

Jun 23, 2014

Begins

Oct 17, 2016

Discovered

Dec 9, 2016

Filed

vs. sector median

4 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.