KALEIDA HEALTH
bd_6206dbbc544100c3 · schema v1 · pii pii-v1
Full breach record for KALEIDA HEALTH →Kaleida Health (Buffalo, NY) reported to HHS OCR on 2017-08-25 a Hacking/IT Incident affecting 744 individuals. Numerous employees were victims of an email phishing scheme that compromised ePHI including names, medical record numbers, dates of birth, diagnoses, Social Security numbers, health insurance information, and treatment information. Breached information was located in Email. No business associate was involved. The CE notified HHS, affected individuals, and the media, revised policies and procedures, and retrained its workforce. OCR obtained assurances corrective actions were implemented.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Aug 25, 2017
Filed
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- HHS OCRbd_ee9181be7785ce742017-07-21 · +35dCandidate
Filing propagation · 2 filings
View merged incident ↗Pattern: first filing Jul 21 (NY), last Aug 25 (NY) — a 35-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.