ALPhysicalHealthcareHealthcareTheftCustomer Data InvolvedHEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNTMediumResolved
Rape & Brooks Orthodontics, P.C.
bd_54ae69286da4d429 · schema v1 · pii pii-v1
Full breach record for Rape & Brooks Orthodontics, P.C. →On February 4, 2011, Rape & Brooks Orthodontics, P.C. (AL) experienced a physical break-in during which a computer server, three desktop computers, and an external hard drive were stolen, affecting the demographic, clinical, and financial information of approximately 20,744 individuals. The CE notified HHS, affected individuals, and the media. Remediation included upgraded physical security, locked server storage, password protection, and encryption of external drives. OCR reviewed the CE's HIPAA policies and procedures.
HIPAA clock✓ HHS notified7 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed20,744 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 28, 2011
- Raw hash
- 93bb5177deffab6519936a07b941fb5b6c58b479611250eb4813aec90eb45a65
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Rape & Brooks Orthodontics, P.C.norm: rape brooks orthodontics
- Industry
- Health Care Services
Victim entity
- Name
- Rape & Brooks Orthodontics, P.C.norm: rape brooks orthodontics
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Feb 4, 2011
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 20,744
- Data types
- HEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- External
- Regulator citations
- HHS OCR obtained and reviewed the CE's relevant HIPAA policies and procedures.
Compliance
- Time to disclose
- 7 weeks(52 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Feb 4, 2011→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.