DisclosureLens
KANSASPhysicalHealthcareGovernmentHealthcareTheftCustomer Data InvolvedHealth (basic)Identity (basic)MediumResolved

Kansas Department on Aging

bd_6742327ac2a2ccdb · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jan 13, 2012

Filed

Jan 19, 2012

To disclose

6 days

Affected

7,757

Confidence

98%
Full breach record for Kansas Department on Aging2 incidents on file

On January 13, 2012, a laptop was stolen from an employee's vehicle at the Kansas Department on Aging (KDOA). The laptop contained ePHI of approximately 7,757 customers, including names, addresses, dates of birth, service types, case manager info, quality review dates, and staff names. KDOA filed a police report, notified HHS and affected individuals, and issued substitute notice. Post-breach, KDOA encrypted all laptops and flash drives and retrained staff. OCR determined KDOA does not meet the definition of a covered entity. Breached information located on Laptop.

HIPAA clock HHS report on time6 days discovery → filing
occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.

Incident timeline

discovery → filing · 6 days

Jan 13, 2012

Begins

Jan 13, 2012

Discovered

Jan 19, 2012

Filed

vs. sector median

12 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed7,757 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.