CALIFORNIAAccidentalHealthcareHealthcareMisdeliveryCustomer Data InvolvedIDENTITY_BASICMETADATALowResolved
Alicia Ann Oswald
bd_463be8d0947035b8 · schema v1 · pii pii-v1
Full breach record for Alicia Ann Oswald →Dr. Alicia Ann Oswald (CA healthcare provider) reported to HHS OCR on 2018-01-09 an Unauthorized Access/Disclosure affecting ~800 individuals. She sent group emails to patients without using BCC, inadvertently exposing recipient email addresses. Breached information was located in Email. In response, she re-sent using BCC, apologized to patients, reported to the CA State Board, adopted improved email software, and deployed practice software to safeguard PHI. OCR confirmed corrective actions and provided HIPAA Breach Notification Rule guidance.
HIPAA clock✓ HHS notified
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed800 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jan 9, 2018
- Raw hash
- f992a8cd1d52c5f72492429a994947e425c0a3fd6d46bff13b44d93eb22d0dd0
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Alicia Ann Oswaldnorm: alicia ann oswald
- Industry
- Health Care Services
Victim entity
- Name
- Alicia Ann Oswaldnorm: alicia ann oswald
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- Jan 9, 2018
- Affected individuals
- 800
- Data types
- IDENTITY_BASICMETADATA
- Attack vector
- Unauthorized Access
- Threat actor
- Internal
- Regulator citations
- Reported to California State BoardBreach notification submitted to HHS OCROCR obtained CE HIPAA Notice of Privacy Practices PolicyOCR provided technical assistance on HIPAA Breach Notification Rule requirements
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: Jan 9, 2018— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.