DisclosureLens
CALIFORNIAPhysicalHealthcareHealthcareTheftCustomer Data InvolvedDelayed DiscoveryIdentity (basic)Government IDHealth (basic)MediumResolved

Imperial Valley Family Care Medical Group, APC

bd_4b8a442a5e05fa07 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Mar 21, 2015

Filed

May 13, 2016

To disclose

14 months

Affected

649

Confidence

98%
Full breach record for Imperial Valley Family Care Medical Group, APC2 incidents on file

Imperial Valley Family Care Medical Group, APC (CA) reported to HHS on 2016-05-13 a Theft affecting 649 individuals. On March 21, 2015, an unknown individual broke into a physician's office and stole a laptop containing PHI including names, addresses, Social Security numbers, dates of birth, and clinical information. The CE disabled server access, notified affected individuals and the media, offered one year of free credit monitoring, encrypted all company-issued laptops, and improved physical safeguards per OCR assurances. Breached information located on Laptop.

HIPAA clock HHS report late14 months discovery → filing
occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.

Incident timeline

discovery → filing · 14 months / 419 days

Mar 21, 2015

Begins

Mar 21, 2015

Discovered

May 13, 2016

Filed

vs. sector median

+48 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed649 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.