Iowa Department of Health and Human Services
bd_6a01b24cf32f8f1f · schema v1 · pii pii-v1
Full breach record for Iowa Department of Health and Human Services →Iowa Department of Human Services reported to HHS OCR on 2014-03-10 a breach (type: Other) affecting 2,042 individuals. From February 5, 2010 to January 17, 2014, employees used personal email accounts, personal online storage accounts, and personal electronic devices for work purposes, transferring PHI outside the CE's secure network. Breached info included names, mailing addresses, SSNs, state ID numbers, dates of birth, case assessment PHI, and incident information. Located on Email, Laptop, and Other Portable Electronic Devices. No business associate was present. Affected individuals were notified, media was notified, and free credit monitoring was offered. OCR has consolidated this breach with another breach involving this CE.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 10, 2014
- Raw hash
- 9714951577044d9722d09a0b2d2bf156de51595484f56bfa72406d83f6119c03
Source filing
Reporting entity
- Name
- Iowa Department of Health and Human Servicesnorm: iowa department of health and human
- Industry
- Insurance — Health
Victim entity
- Name
- Iowa Department of Health and Human Servicesnorm: iowa department of health and human
- Industry
- Insurance — Health
- Industry
- Healthcaresource defaultGovernmentllm
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 2,042
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unknown
- Threat actor
- Internal
- Regulator citations
- OCR has consolidated this breach with another breach involving this CE.
- Initial access
- insider_action
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.