Complete Medical Homecare
bd_711a4494e1880a7b · schema v1 · pii pii-v1
Full breach record for Complete Medical Homecare →On December 12, 2013, Complete Medical Homecare (KS) delivered in error a portable computer drive containing PHI — including electronic medical records with patient names, addresses, medical diagnoses, and in some cases Social Security numbers — to its business partner, All American Medical Supplies (AAMS). AAMS accessed the drive but subsequently deleted the data and returned it. Approximately 1,700 individuals were affected. HHS OCR investigated; the CE implemented new HIPAA policies. The CE legally dissolved on December 23, 2015. Breach submitted to HHS on 2014-01-21.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jan 21, 2014
- Raw hash
- 82467506e7e0921dd694ea09954f3bdd7ac466040d56c906276cc8da4893bd6c
Source filing
Reporting entity
- Name
- Complete Medical Homecarenorm: complete medical homecare
- Industry
- Health Care Services
Victim entity
- Name
- Complete Medical Homecarenorm: complete medical homecare
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Dec 12, 2013
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,700
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access· All American Medical Supplies (AAMS)
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- Partner
- Regulator citations
- HHS OCR investigation conducted; CE required to develop breach notification, training, hardware removal, and encryption/decryption policies and procedures.
- Third party
- via All American Medical Supplies (AAMS)
- Initial access
- insider_action
Compliance
- Time to disclose
- 6 weeks(40 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Dec 12, 2013→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.