Midwest Orthopedic Pain and Spine
bd_46ccda73499c181f · schema v1 · pii pii-v1
Full breach record for Midwest Orthopedic Pain and Spine →Midwest Orthopedic Pain and Spine (MO) reported a Hacking/IT Incident to HHS OCR on 2016-07-26 affecting 29,153 individuals. The CE learned of the breach via FBI notification on May 27, 2016. The suspected vector was a third-party company with database access for patient record transfers. PHI exposed on a network server included names, addresses, dates of birth, SSNs, driver's license numbers, and clinical information. The CE replaced its IT/billing/EMR vendors, deployed new firewalls, began continuous server monitoring, and retrained staff on HIPAA.
J jump to incidentP pin to compareR raw source
Incident timeline
May 27, 2016
Discovered
Jul 26, 2016
Filed
vs. sector median
4 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.