ALMisuseHealthcareGovernmentHealthcarePrivilege AbuseData MishandlingCustomer Data InvolvedData ExfiltratedTargetedHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTHighResolved
Alabama Department of Public Health
bd_4c5ae6ed3f1e253d · schema v1 · pii pii-v1
Full breach record for Alabama Department of Public Health →Alabama Department of Public Health reported to HHS OCR on 2014-06-26 a Theft (insider disclosure) affecting approximately 1,200 individuals. An employee disclosed PHI from Electronic Medical Records to a third party, potentially for tax fraud purposes. Federal law enforcement informed the entity on 2014-03-21. The employee was criminally indicted by the U.S. District Court, Middle District of Alabama, and is no longer employed. Additional safeguards were implemented.
HIPAA clock✓ HHS notified14 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,200 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jun 26, 2014
- Raw hash
- cda0062d80155957f61abc0a5cd7d46ca200180f984277f20f47386c5d7285ad
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Alabama Department of Public Healthnorm: alabama department of public health
- Industry
- Health Care Services
Victim entity
- Name
- Alabama Department of Public Healthnorm: alabama department of public health
- Industry
- Health Care Services
- Industry
- Healthcaresource defaultGovernmentllm
Incident
- Discovered
- Mar 21, 2014
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,200
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- Threat actor
- InternalFinancial
- Regulator citations
- HHS OCR breach notification filed 2014-06-26
- Initial access
- insider_action
Compliance
- Time to disclose
- 14 weeks(97 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Mar 21, 2014→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.