University of Kentucky - UK HealthCare
bd_6c2a19cd32826bfc · schema v1 · pii pii-v1
Full breach record for University of Kentucky - UK HealthCare →On May 1, 2012, an unencrypted laptop belonging to a University of Kentucky HealthCare employee was stolen after a workforce member's son borrowed it without permission, knowing the computer's password. The PHI of approximately 4,488 individuals was exposed, including medical record numbers, dates of visits, and chief complaints. The covered entity notified HHS, the media, and affected individuals, revised its HIPAA and mobile device policies, implemented risk-based security measures, and provided employee training. The responsible workforce member ultimately resigned. OCR obtained assurances that all corrective actions were completed. Location of breached info: Laptop.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jun 19, 2012
- Raw hash
- ceda9f973a6c35497596bd655c45b210602e9db3d9ddc6d402e80d8f7a727a72
Source filing
Reporting entity
- Name
- University of Kentucky - UK HealthCarenorm: university of kentucky uk healthcare
- Domain
- ukhealthcare.uky.edu
- Industry
- Health Care Services
Victim entity
- Name
- University of Kentucky - UK HealthCarenorm: university of kentucky uk healthcare
- Domain
- ukhealthcare.uky.edu
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- May 1, 2012
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 4,490
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- Internal
- Regulator citations
- HHS OCR — breach notification submitted; OCR obtained assurances that corrective actions were completed
- Initial access
- insider_action
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: May 1, 2012→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.