Gillette Medical Imaging
bd_7782d4b168bcf84e · schema v1 · pii pii-v1
Full breach record for Gillette Medical Imaging →On December 1, 2017, Gillette Medical Imaging (Gillette, WY) discovered that its former business associate mistakenly mailed medical billing records to other providers in the same geographic area. The breach affected 4,476 individuals and exposed names, addresses, SSNs, dates of birth, insurance claims information, bank and credit card account numbers, diagnoses, lab results, and medications. Breached information was located on Paper/Films. OCR verified proper BA agreements were in place and provided technical assistance to resolve the breach. Reported to HHS on 2018-01-18.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jan 18, 2018
- Raw hash
- b5604cd07082f56fc8e199e356c3040884e3f8cddd3bde1d74ab84221093a584
Source filing
Reporting entity
- Name
- Gillette Medical Imagingnorm: gillette medical imaging
- Industry
- Health Care Services
Victim entity
- Name
- Gillette Medical Imagingnorm: gillette medical imaging
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Dec 1, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 4,476
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- Threat actor
- Partner
- Regulator citations
- HHS OCR breach notification submittedOCR verified proper BA agreements were in placeOCR provided technical assistance on reasonable safeguards, device and media controls, disclosures to business associates, BA agreements, reportable breach assessment, and the Breach Notification Rule
Compliance
- Time to disclose
- 7 weeks(48 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Dec 1, 2017→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.