Hartford HealthCare
bd_474c19ddf7f53042 · schema v1 · pii pii-v1
Full breach record for Hartford HealthCare →The covered entity (CE), Hartford HealthCare, reported that several employees were the victims of an email phishing scheme that affected the electronic protected health information (ePHI) of 2,651 individuals. The ePHI involved included names, dates of birth, diagnoses, health insurance information, Social Security numbers, and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice. As a result of this incident, the CE implemented additional administrative, technical, and security safeguards to better protect its ePHI.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Apr 13, 2020
- Raw hash
- 2cd1ba9f089a3d21c3c9036693918ed049a66da7a7f6e59c6700e65f76e76667
Source filing
Reporting entity
- Name
- Hartford HealthCarenorm: hartford healthcare
- Industry
- Health Care Services
Victim entity
- Name
- Hartford HealthCarenorm: hartford healthcare
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 2,651
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- Threat actor
- External
- Regulator citations
- Notified HHS
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.