CALIFORNIAPhysicalHealthcareHealthcareTheftCustomer Data InvolvedHEALTH_BASICIDENTITY_BASICLowResolved
Denise M. Bowden, LAc
bd_4c4b7c79167969a8 · schema v1 · pii pii-v1
Full breach record for Denise M. Bowden, LAc →On April 28, 2018, a burglar stole a desktop computer from the office of Denise M. Bowden, LAc, a licensed acupuncturist in CA. The computer contained PHI of 538 individuals, including demographic and clinical information. The CE notified police and provided breach notifications to HHS, affected individuals, and media, and offered free credit monitoring. Following OCR's investigation, the CE reset passcodes, implemented MFA, installed a security camera, trained staff, and updated policies for safeguarding PHI.
HIPAA clockDiscovered Apr 28, 2018 → Notified Jun 11, 201844d ✓ HIPAA 60-day OK6 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_323ea204580b0808California State AGfiled 2018-06-11Verified by operator
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jun 11, 2018
- Raw hash
- 9f619870e3f26426de23ad64c7d0e925d51cafb959ebaaa935594249acc3e77b
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Denise M. Bowden, LAcnorm: denise m bowden lac
- Industry
- Health Care Services
Victim entity
- Name
- Denise M. Bowden, LAcnorm: denise m bowden lac
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Apr 28, 2018
- Materiality determined
- —
- Notification sent
- Jun 11, 2018
- Affected individuals
- 538
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- ExternalFinancial
- Regulator citations
- HHS OCR investigation; CE reset passcodes, implemented multi-factor authentication, installed security camera, trained staff, and provided OCR with copies of policies and procedures for safeguarding PHI.
Compliance
- Time to disclose
- 6 weeks(44 days from discovery to filing)
- Compliance flags
- HIPAA 60-day OK · 44dHHS notified · 44d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Apr 28, 2018→ Notified: Jun 11, 201844d 60 days HIPAA 60-day OK HIPAA Discovered: Apr 28, 2018→ Notified: Jun 11, 201844d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.