Sentara Healthcare
bd_618c2e2ad888d727 · schema v1 · pii pii-v1
Full breach record for Sentara Healthcare →Sentara Healthcare (VA) reported to HHS OCR on 2015-10-02 a theft affecting 1,040 individuals. On or about August 14, 2015, two external computer hard drives were stolen from the covered entity's electrophysiology labs. The PHI included patients' names, dates of birth, unique identification numbers, and treatment information. Breached information was located on Other Portable Electronic Device. The CE improved physical access controls, eliminated the need for external hard drives, and notified HHS, affected individuals, and the media. OCR reviewed the risk assessment and confirmed corrective actions.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Oct 2, 2015
- Raw hash
- 26f8e2f87c9f6eb09f3d0dfc1d9744af9b8b2f0b4ce504e7588e776e0c3bb820
Source filing
Reporting entity
- Name
- Sentara Healthcarenorm: sentara healthcare
- Domain
- sentara.com
- Industry
- Health Care Services
Victim entity
- Name
- Sentara Healthcarenorm: sentara healthcare
- Domain
- sentara.com
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Aug 14, 2015
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,040
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- External
- Regulator citations
- HHS OCR reviewed risk assessment and obtained assurances of corrective actions
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Aug 14, 2015→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.