CALIFORNIAHackingHealthcareHealthcareCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
RADY CHILDREN'S HOSPITAL SAN DIEGO
bd_50d81353ec6275ba · schema v1 · pii pii-v1
Full breach record for RADY CHILDREN'S HOSPITAL SAN DIEGO →Rady Children's Hospital San Diego reported to HHS on 2020-02-21 a Unauthorized Access/Disclosure affecting 2360 individuals. Breached information located on Network Server. A vulnerability on the network server allowed ePHI (names, financial, and treatment info) to be accessible via the Internet. The entity notified HHS, individuals, and media, provided credit monitoring, and implemented additional safeguards.
HIPAA clockDiscovered Feb 21, 2020 → Notified Feb 21, 20200d ✓ HHS notified≤1 day discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_97f45a0d9ce3b6e0California State AGfiled 2020-02-21Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Feb 21, 2020
- Raw hash
- 8ed91f6e41934c2e32dc924c1cd8dd79f11da042cb7e516fac4b7d0942660c8f
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- RADY CHILDREN'S HOSPITAL SAN DIEGOnorm: rady children s hospital san diego
- Industry
- Health Care Services
Victim entity
- Name
- RADY CHILDREN'S HOSPITAL SAN DIEGOnorm: rady children s hospital san diego
- Industry
- Healthcaresource default
Incident
- Discovered
- Feb 21, 2020
- Materiality determined
- —
- Notification sent
- Feb 21, 2020
- Affected individuals
- 2,360
- Data types
- PHIHEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified HHS
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- ≤1 day(0 days from discovery to filing)
- Compliance flags
- HHS notified · 0dHIPAA 60-day OK · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Feb 21, 2020→ Notified: Feb 21, 20200d regulatory submission HHS notified HIPAA Discovered: Feb 21, 2020→ Notified: Feb 21, 20200d 60 days HIPAA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.