DisclosureLens
MISSOURIHackingHealthcareHealthcareCustomer Data InvolvedSupply Chain (3P Vendor)Delayed DiscoveryHealth (basic)Identity (basic)Government IDHighResolved

Midwest Orthopedic Pain and Spine

bd_46ccda73499c181f · schema v1 · pii pii-v1

Severity

High

Discovered

May 27, 2016

Filed

Jul 26, 2016

To disclose

9 weeks

Affected

29,153

Confidence

94%
Full breach record for Midwest Orthopedic Pain and Spine

Midwest Orthopedic Pain and Spine (MO) reported a Hacking/IT Incident to HHS OCR on 2016-07-26 affecting 29,153 individuals. The CE learned of the breach via FBI notification on May 27, 2016. The suspected vector was a third-party company with database access for patient record transfers. PHI exposed on a network server included names, addresses, dates of birth, SSNs, driver's license numbers, and clinical information. The CE replaced its IT/billing/EMR vendors, deployed new firewalls, began continuous server monitoring, and retrained staff on HIPAA.

HIPAA clock HHS report on time9 weeks discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

discovery → filing · 9 weeks / 60 days

May 27, 2016

Discovered

Jul 26, 2016

Filed

vs. sector median

4 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed29,153 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.