MASSACHUSETTSHackingHealthcareHealthcareCustomer Data InvolvedDelayed DiscoveryHEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNTMediumResolved
Cambridge Health Alliance
bd_371668e16d65215c · schema v1 · pii pii-v1
Full breach record for Cambridge Health Alliance →Cambridge Health Alliance (MA) reported to HHS on 2018-03-28 a Hacking/IT Incident affecting 2,280 individuals. In 2017, the Everett Police found a computer hard drive containing PHI of 2,280 patients. The CE's security team found no identifiable egress path. PHI included patient billing and clinical information from 2013 related to emergency department visits. OCR obtained assurances the CE is reviewing its HIPAA Privacy and Security training. Breached information located on Other media.
HIPAA clockDiscovered Jan 1, 2017 → Notified Mar 28, 2018451d ✗ HIPAA 60-day late15 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2,280 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 28, 2018
- Raw hash
- 7d516ac257e423ff3eda94d4e9ece8e8dd41a392dbd478212a4465c01aed0377
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Cambridge Health Alliancenorm: cambridge health alliance
- Industry
- Health Care Services
Victim entity
- Name
- Cambridge Health Alliancenorm: cambridge health alliance
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Jan 1, 2017
- Materiality determined
- —
- Notification sent
- Mar 28, 2018
- Affected individuals
- 2,280
- Data types
- HEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- Regulator citations
- OCR obtained assurances regarding HIPAA Privacy and Security training review
Compliance
- Time to disclose
- 15 months(451 days from discovery to filing)
- Compliance flags
- HIPAA 60-day late · 451dHHS notified · 451d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jan 1, 2017→ Notified: Mar 28, 2018451d 60 days HIPAA 60-day late HIPAA Discovered: Jan 1, 2017→ Notified: Mar 28, 2018451d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.