Children's Hospital Colorado
bd_5a374454ce801578 · schema v1 · pii pii-v1
Full breach record for Children's Hospital Colorado →Children's Hospital Colorado reported to HHS OCR on 2017-09-08 a Hacking/IT Incident (email phishing) affecting 3,370 individuals' PHI stored in email accounts. OCR investigation found MFA was disabled on a compromised account. OCR imposed a $548,265 civil money penalty. Breached info located in Email. No business associate was involved. The entity is a pediatric hospital, so minor patient records are implicated.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Sep 8, 2017
Filed
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Illinois State AGbd_98e5159e8e96818b2020-01-01 · +845dVerified by operator
- Illinois State AGbd_df63f008f995cb7f2020-01-01 · +845dVerified by operator
- HHS OCRbd_f6f54a270eb5a37a2020-07-27 · +1053dCandidate
- HHS OCR enforcementbd_daf381098a786d942024-12-05 · +2645dVerified by operator
Filing propagation · 5 filings · 2 states
View merged incident ↗Pattern: first filing Sep 8 (CO), last Dec 5 — a 2645-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.