Kansas Department on Aging
bd_6742327ac2a2ccdb · schema v1 · pii pii-v1
Full breach record for Kansas Department on Aging →On January 13, 2012, a laptop was stolen from an employee's vehicle at the Kansas Department on Aging (KDOA). The laptop contained ePHI of approximately 7,757 customers, including names, addresses, dates of birth, service types, case manager info, quality review dates, and staff names. KDOA filed a police report, notified HHS and affected individuals, and issued substitute notice. Post-breach, KDOA encrypted all laptops and flash drives and retrained staff. OCR determined KDOA does not meet the definition of a covered entity. Breached information located on Laptop.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jan 19, 2012
- Raw hash
- 13b7ec44b0acc8f89f9478e7dc2598485628fc871f6cbb2120310ddcc1e681da
Source filing
Reporting entity
- Name
- Kansas Department on Agingnorm: kansas department on aging
- Industry
- Health Care Services
Victim entity
- Name
- Kansas Department on Agingnorm: kansas department on aging
- Industry
- Health Care Services
- Industry
- Healthcaresource defaultGovernmentllm
Incident
- Discovered
- Jan 13, 2012
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 7,757
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- External
- Regulator citations
- HHS OCR investigation; OCR obtained assurances of corrective action; OCR determined KDOA does not meet the definition of a covered entity.
Compliance
- Time to disclose
- 6 days(6 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jan 13, 2012→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.