Graphium Health
bd_4faf9a09d8a78d3a · schema v1 · pii pii-v1
Full breach record for Graphium Health →Graphium Health (UT) reported to HHS OCR on 2025-03-20 an Unauthorized Access/Disclosure breach affecting 1,187 individuals. PHI was emailed to the wrong recipient (misdelivery); breached information was on Paper/Films. Exposed data included names, providers, and dates and costs of service. The CE notified HHS, affected individuals, and the media, provided substitute notice, and implemented additional technical safeguards. A business associate was present.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Mar 20, 2025
Filed
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.