HP Enterprise Services
bd_72cdf701cffd4cbe · schema v1 · pii pii-v1
HP Enterprise Services (Business Associate, KY) reported to HHS on 2012-12-28 a Theft affecting 1,090 individuals. An employee of a subcontractor responded to a telephone phishing (vishing) attack and permitted a hacker to remotely access the subcontractor's laptop, which improperly stored PHI including names, dates of birth, diagnosis codes, SSNs, and treatment descriptions. The subcontractor terminated the responsible employee, initiated laptop PHI audits, and retrained staff. OCR obtained assurances that corrective actions were completed. Breached information located on Laptop.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Dec 28, 2012
Filed
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.