Kansas Department on Aging
bd_6742327ac2a2ccdb · schema v1 · pii pii-v1
Full breach record for Kansas Department on Aging →2 incidents on fileOn January 13, 2012, a laptop was stolen from an employee's vehicle at the Kansas Department on Aging (KDOA). The laptop contained ePHI of approximately 7,757 customers, including names, addresses, dates of birth, service types, case manager info, quality review dates, and staff names. KDOA filed a police report, notified HHS and affected individuals, and issued substitute notice. Post-breach, KDOA encrypted all laptops and flash drives and retrained staff. OCR determined KDOA does not meet the definition of a covered entity. Breached information located on Laptop.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 13, 2012
Begins
Jan 13, 2012
Discovered
Jan 19, 2012
Filed
vs. sector median
12 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.