Iowa Dept. of Human Services
bd_6a01b24cf32f8f1f · schema v1 · pii pii-v1
Iowa Department of Human Services reported to HHS OCR on 2014-03-10 a breach (type: Other) affecting 2,042 individuals. From February 5, 2010 to January 17, 2014, employees used personal email accounts, personal online storage accounts, and personal electronic devices for work purposes, transferring PHI outside the CE's secure network. Breached info included names, mailing addresses, SSNs, state ID numbers, dates of birth, case assessment PHI, and incident information. Located on Email, Laptop, and Other Portable Electronic Devices. No business associate was present. Affected individuals were notified, media was notified, and free credit monitoring was offered. OCR has consolidated this breach with another breach involving this CE.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 5, 2010
Begins
Mar 10, 2014
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.