Tulare County Health & Human Services Agency
bd_4cbb903197b7a6a4 · schema v1 · pii pii-v1
Full breach record for Tulare County Health & Human Services Agency →Tulare County Health & Human Services Agency (CA) reported to HHS OCR on 2015-04-02 an Unauthorized Access/Disclosure affecting 845 individuals. A workforce member emailed patients information about logging into the CE's healthcare portal without blind-copying recipients or encrypting the emails, thereby exposing every patient's email address. Breached information was located in Email. The CE notified HHS, affected individuals, and the media. Corrective actions included password hardening, portal account resets, new technical safeguards, policy revisions, and workforce retraining. OCR provided technical assistance and obtained documented assurances of remediation.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_ea5a543c5b2c2549California State AGfiled 2015-04-06(4d gap)Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Apr 2, 2015
- Raw hash
- 0238a38161f3cfa04f15599399839ae606a9059c9e4e0df81ba39478b4bb4423
Source filing
Reporting entity
- Name
- Tulare County Health & Human Services Agencynorm: tulare county health human services agency
- Domain
- tchhsa.org
- Industry
- Health Care Services
Victim entity
- Name
- Tulare County Health & Human Services Agencynorm: tulare county health human services agency
- Domain
- tchhsa.org
- Industry
- Health Care Services
- Industry
- Healthcaresource defaultGovernmentllm
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 845
- Data types
- HEALTH_BASICIDENTITY_BASICMETADATA
- Attack vector
- Unauthorized Access
- Threat actor
- Internal
- Regulator citations
- OCR provided technical assistance regarding the HIPAA Security Rule and obtained documented assurances that the CE implemented corrective actions.
- Initial access
- insider_action
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.