Port City Operating Company
bd_864cb77470f26eb6 · schema v1 · pii pii-v1
Full breach record for Port City Operating Company →On August 9, 2018, St. Joseph's Medical Center (Port City Operating Company) discovered that hard drives from two old laboratory machine analyzers were missing during removal and replacement. The drives contained ePHI of approximately 4,984 individuals, including names, dates of birth, genders, account information, lab tests, test results, and ordering physicians. The CE and its BA searched facilities and interviewed staff but could not recover the drives. Breach notifications were sent to HHS, affected individuals, and media. The BA updated policies/procedures and retrained staff; OCR confirmed corrective actions. Breached info located on Other Portable Electronic Device.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_707aae194c4b6c4eCalifornia State AGfiled 2018-08-31Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Aug 31, 2018
- Raw hash
- 3f182a3ec86e706c388ce31fe751ef182c5b4691d9ca36944963fc1f37e6de15
Source filing
Reporting entity
- Name
- Port City Operating Companynorm: port city operating
- Industry
- Health Care Services
Victim entity
- Name
- Port City Operating Companynorm: port city operating
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Aug 9, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 4,984
- Data types
- HEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Regulator citations
- OCR obtained assurances that the CE/BA implemented corrective actions including updated policies and procedures and retraining of workforce members.
Compliance
- Time to disclose
- 22 days(22 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Aug 9, 2018→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.