DisclosureLens
IOWAMisuseHealthcareGovernmentHealthcareEmail MisuseUnapproved SoftwareUnapproved HardwareCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryIdentity (basic)Government IDHealth (basic)HighResolved

Iowa Dept. of Human Services

bd_6a01b24cf32f8f1f · schema v1 · pii pii-v1

Severity

High

Discovered

Filed

Mar 10, 2014

To disclose

Affected

2,042

Confidence

95%

Iowa Department of Human Services reported to HHS OCR on 2014-03-10 a breach (type: Other) affecting 2,042 individuals. From February 5, 2010 to January 17, 2014, employees used personal email accounts, personal online storage accounts, and personal electronic devices for work purposes, transferring PHI outside the CE's secure network. Breached info included names, mailing addresses, SSNs, state ID numbers, dates of birth, case assessment PHI, and incident information. Located on Email, Laptop, and Other Portable Electronic Devices. No business associate was present. Affected individuals were notified, media was notified, and free credit monitoring was offered. OCR has consolidated this breach with another breach involving this CE.

HIPAA clock HHS notified
no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.

Incident timeline

Feb 5, 2010

Begins

Mar 10, 2014

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2,042 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.