Colorado Physician Partners, PLLC
bd_418c3e41d274645d · schema v1 · pii pii-v1
Full breach record for Colorado Physician Partners, PLLC →Colorado Physician Partners, PLLC (a Colorado healthcare provider) reported to HHS OCR on 2022-03-25 that an employee fell victim to an email phishing attack, exposing PHI of 12,877 individuals. Affected data included names, Social Security numbers, dates of birth, addresses, diagnoses, prescribed medications, and financial/treatment information. The entity notified HHS, affected individuals, and the media, provided substitute notice and complimentary credit monitoring, implemented additional administrative and technical safeguards, and retrained staff on email security. OCR provided technical assistance on the HIPAA Security Rule.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 25, 2022
- Raw hash
- 5af6f7cf167ad9cb2ae7b207094844d88ceefd5a7e867d0306c10938f694401c
Source filing
Reporting entity
- Name
- Colorado Physician Partners, PLLCnorm: colorado physician
Victim entity
- Name
- Colorado Physician Partners, PLLCnorm: colorado physician
- Industry
- Healthcare Provider
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 12,877
- Data types
- PIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL
- Attack vector
- Phishing
- Threat actor
- ExternalFinancial
- Regulator citations
- HHS OCR breach reportOCR provided technical assistance regarding the HIPAA Security Rule
- Initial access
- phishing_link
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.