DXC TECHNOLOGY COMPANY
bd_72cdf701cffd4cbe · schema v1 · pii pii-v1
Full breach record for DXC TECHNOLOGY COMPANY →HP Enterprise Services (Business Associate, KY) reported to HHS on 2012-12-28 a Theft affecting 1,090 individuals. An employee of a subcontractor responded to a telephone phishing (vishing) attack and permitted a hacker to remotely access the subcontractor's laptop, which improperly stored PHI including names, dates of birth, diagnosis codes, SSNs, and treatment descriptions. The subcontractor terminated the responsible employee, initiated laptop PHI audits, and retrained staff. OCR obtained assurances that corrective actions were completed. Breached information located on Laptop.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Dec 28, 2012
- Raw hash
- d36d1a62897b7606fab469f2597fe7ebdbdcd16d95c1a12943e1673175940421
Source filing
Reporting entity
- Name
- DXC TECHNOLOGY COMPANYnorm: dxc technology
- Domain
- dxc.com
- Industry
- Business Associate
Victim entity
- Name
- DXC TECHNOLOGY COMPANYnorm: dxc technology
- Domain
- dxc.com
- Industry
- Business Associate
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,090
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical MediumT1566 PhishingT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- OCR obtained assurances that corrective action was completed
- Initial access
- external_remote_services
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.