DisclosureLens
CALIFORNIAPhysicalHealthcareHealthcareTheftCustomer Data InvolvedHealth (basic)Identity (basic)LowResolved

Denise M. Bowden, LAc

bd_4c4b7c79167969a8 · schema v1 · pii pii-v1

Severity

Low

Discovered

Apr 28, 2018

Filed

Jun 11, 2018

To disclose

6 weeks

Affected

538

Linked

2 filings

Confidence

98%
Full breach record for Denise M. Bowden, LAc

On April 28, 2018, a burglar stole a desktop computer from the office of Denise M. Bowden, LAc, a licensed acupuncturist in CA. The computer contained PHI of 538 individuals, including demographic and clinical information. The CE notified police and provided breach notifications to HHS, affected individuals, and media, and offered free credit monitoring. Following OCR's investigation, the CE reset passcodes, implemented MFA, installed a security camera, trained staff, and updated policies for safeguarding PHI.

HIPAA clockDiscovered Apr 28, 2018Notified Jun 11, 201844d HHS report on time6 weeks discovery → filing
occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.

Incident timeline

discovery → filing · 6 weeks / 44 days

Apr 28, 2018

Begins

Apr 28, 2018

Discovered

Jun 11, 2018

Filed

vs. sector median

6 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings

View merged incident ↗
California State AGJun 11 · first
HHS OCRJun 11 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.