WISCONSINPhysicalHealthcareHealthcareTheftCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTHighResolved
Laboratory Corporation of America/Dynacare Northwest, Inc.
bd_3f083252c9d9b66f · schema v1 · pii pii-v1
Full breach record for Laboratory Corporation of America/Dynacare Northwest, Inc. →United Dynacare, LLC dba Dynacare Laboratories reported to HHS on 2013-11-18 a Theft affecting 9328 individuals. Breached information located on Other Portable Electronic Device. An employee's car containing an unencrypted flash drive with patient PHI was stolen. No unauthorized access was found upon recovery.
HIPAA clockDiscovered Oct 22, 2013 → Notified Nov 18, 201327d ✓ HHS notified27 days discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed9,328 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Nov 18, 2013
- Raw hash
- 20d71f4203c4cbd72e287b91ecd937a877d35e8fd6e4d4b66ead75dc8c00c746
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Laboratory Corporation of America/Dynacare Northwest, Inc.norm: laboratory corporation of america dynacare northwest
- Domain
- labcorp.com
- Industry
- Health Care Services
Victim entity
- Name
- Laboratory Corporation of America/Dynacare Northwest, Inc.norm: laboratory corporation of america dynacare northwest
- Domain
- labcorp.com
- Industry
- Healthcaresource default
Incident
- Discovered
- Oct 22, 2013
- Materiality determined
- —
- Notification sent
- Nov 18, 2013
- Affected individuals
- 9,328
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- Internal
- Regulator citations
- provided breach notification to HHSOCR obtained assurances that the CE implemented the corrective actions listed above
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- HHS notified · 27dHIPAA 60-day OK · 27d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Oct 22, 2013→ Notified: Nov 18, 201327d regulatory submission HHS notified HIPAA Discovered: Oct 22, 2013→ Notified: Nov 18, 201327d 60 days HIPAA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.