CALIFORNIAPhysicalHealthcareHealthcareTheftCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumResolved
Imperial Valley Family Care Medical Group, APC
bd_4b8a442a5e05fa07 · schema v1 · pii pii-v1
Full breach record for Imperial Valley Family Care Medical Group, APC →Imperial Valley Family Care Medical Group, APC (CA) reported to HHS on 2016-05-13 a Theft affecting 649 individuals. On March 21, 2015, an unknown individual broke into a physician's office and stole a laptop containing PHI including names, addresses, Social Security numbers, dates of birth, and clinical information. The CE disabled server access, notified affected individuals and the media, offered one year of free credit monitoring, encrypted all company-issued laptops, and improved physical safeguards per OCR assurances. Breached information located on Laptop.
HIPAA clock✓ HHS notified14 months discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed649 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 13, 2016
- Raw hash
- e0376be298e721cae6e885f8b4c5e4b76e2f0dbe0c11d7c0924df46cd4f9d2c1
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Imperial Valley Family Care Medical Group, APCnorm: imperial valley family care medical group apc
- Industry
- Health Care Services
Victim entity
- Name
- Imperial Valley Family Care Medical Group, APCnorm: imperial valley family care medical group apc
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Mar 21, 2015
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 649
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- External
- Regulator citations
- HHS OCR notified per Breach Notification RuleOCR obtained assurances that the CE improved physical safeguards, revised its encryption policy, and strengthened its password requirements for electronic systems or devices containing electronic PHI
Compliance
- Time to disclose
- 14 months(419 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Mar 21, 2015→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.