Spectrum Health System
bd_34018e3cec511527 · schema v1 · pii pii-v1
Full breach record for Spectrum Health System →On June 22, 2017, a digital camera containing photographs of patients' chart labels and skin conditions was stolen from a physician's vehicle parked outside the physician's home. The camera held PHI created between February 15 and June 21, 2017, affecting 902 individuals' demographic and clinical information. Spectrum Health System (MI) submitted breach notification to HHS on August 3, 2017. Breached information was located on another portable electronic device. The CE notified affected individuals and media, posted substitute notice, and established a call center. Corrective actions included mobile device encryption policies, camera removal ban, and a 2018–2019 enterprise-wide risk analysis. OCR obtained documented assurances of compliance.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Aug 3, 2017
- Raw hash
- 94e0f28739198de084f765709fae153517d836540d0d7126de872451058ea362
Source filing
Reporting entity
- Name
- Spectrum Health Systemnorm: spectrum health system
- Industry
- Health Care Services
Victim entity
- Name
- Spectrum Health Systemnorm: spectrum health system
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Jun 22, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 902
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- External
- Regulator citations
- HHS OCR — breach notification submitted; OCR obtained documented assurances of corrective actions
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jun 22, 2017→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.