DisclosureLens
TENNESSEEMisuseHealthcareHealthcarePrivilege AbuseStolen CredentialsBusiness Associate (HIPAA)Customer Data InvolvedDelayed DiscoveryIdentity (basic)Government IDHealth (basic)HighResolved

Professional Counseling & Medical Associates

bd_4f391257e59210df · schema v1 · pii pii-v1

Severity

High

Discovered

Filed

Jul 13, 2017

To disclose

Affected

2,500

Confidence

96%
Full breach record for Professional Counseling & Medical Associates

Professional Counseling & Medical Associates (TN) reported to HHS on 2017-07-13 a Hacking/IT Incident affecting 2,500 individuals. A former contractor continued to access the CE's electronic health records system after her employment ended on May 12, 2017, exposing PHI of 2,605 individuals including names, addresses, dates of birth, driver's license numbers, patient IDs, claims, diagnoses, lab results, medications, and treatment info. Breached information located on Electronic Medical Record. A business associate was present. OCR obtained assurances that corrective actions were implemented.

HIPAA clock HHS notified
no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.

Incident timeline

May 12, 2017

Begins

Jul 13, 2017

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2,500 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.