Kirkbride Center
bd_6de78cbd9b3aa021 · schema v1 · pii pii-v1
Full breach record for Kirkbride Center →Kirkbride Center (PA) reported to HHS on 2014-11-19 a Theft affecting 860 individuals. In August 2014, an Assistant U.S. Attorney notified the CE that an individual arrested in Florida possessed hard copies of the CE's daily census reports containing patient names, dates of birth, and some SSNs (~869 individuals). The CE's investigation determined a rogue employee stole the reports. The convict was found guilty of identity theft. Breached info located on Paper/Films. The CE notified HHS, media, and patients; offered one year of free identity theft protection; and revised its billing and report-distribution processes per OCR's investigation.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Nov 19, 2014
- Raw hash
- caa4f8ace940abfa6ef6b1ac0b7621d1d31226dc45dbe938d6221cc33e71a326
Source filing
Reporting entity
- Name
- Kirkbride Centernorm: kirkbride center
- Industry
- Health Care Services
Victim entity
- Name
- Kirkbride Centernorm: kirkbride center
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Aug 1, 2014
- Materiality determined
- —
- Notification sent
- Nov 19, 2014
- Affected individuals
- 860
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- InternalFinancial
- Regulator citations
- HHS OCR investigation conducted; CE revised billing software and report distribution process as a result
- Initial access
- insider_action
Compliance
- Time to disclose
- 16 weeks(110 days from discovery to filing)
- Compliance flags
- HIPAA 60-day late · 110dHHS notified · 110d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Aug 1, 2014→ Notified: Nov 19, 2014110d 60 days HIPAA 60-day late HIPAA Discovered: Aug 1, 2014→ Notified: Nov 19, 2014110d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.