ILAccidentalHealthcareHealthcareMisconfigurationCustomer Data InvolvedDelayed DiscoveryHEALTH_BASICIDENTITY_BASICLowResolved
Chicago Muscoskeletal Institute
bd_8670c6df5a30ead3 · schema v1 · pii pii-v1
Full breach record for Chicago Muscoskeletal Institute →Chicago Musculoskeletal Institute reported to HHS on 2012-03-23 an Unauthorized Access/Disclosure affecting 750 individuals. On December 31, 2011, patient names, dates of birth, medical record numbers, and clinic notes were inadvertently exposed on the CE's network server and website. The CE disabled the website, removed the data, and notified HHS, affected individuals, and the media. Following OCR investigation, the CE provided fraud and credit monitoring to patients and retrained staff on technical safeguards. Breached information located on Network Server.
HIPAA clock✓ HHS notified12 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed750 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 23, 2012
- Raw hash
- 81ac5a6885839f5d32dfd8a63f10ef71384a6e2be551c0047cee447c899087bb
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Chicago Muscoskeletal Institutenorm: chicago muscoskeletal institute
- Industry
- Health Care Services
Victim entity
- Name
- Chicago Muscoskeletal Institutenorm: chicago muscoskeletal institute
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Dec 31, 2011
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 750
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- Regulator citations
- OCR investigation conducted; OCR required CE to provide fraud and credit monitoring to affected individuals and retrain staff on technical safeguards
Compliance
- Time to disclose
- 12 weeks(83 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Dec 31, 2011→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.