Virginia Commonwealth University Health System Authority
bd_8dd27b5590ae2f59 · schema v1 · pii pii-v1
Full breach record for Virginia Commonwealth University Health System Authority →Virginia Commonwealth University Health System (VA) reported to HHS on 2017-03-10 an Unauthorized Access/Disclosure affecting 2,716 individuals via Electronic Medical Records. An employee of a community physician and an employee of a contracted vendor independently accessed patient records without a legitimate business need. PHI potentially viewed included full names, home addresses, dates of birth, medical record numbers, providers, visit dates, health insurance information, and diagnostic/treatment information. No malicious intent was confirmed and no data was retained. The CE implemented additional safeguards, removed browse functionality, and minimized search results. OCR obtained assurances of corrective action.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 10, 2017
- Raw hash
- 14570c9388a6a62e73c01d54916103e2e8ef4ae5bf377dd646164a6a2fbb49cd
Source filing
Reporting entity
- Name
- Virginia Commonwealth University Health System Authoritynorm: virginia commonwealth university health system authority
- Domain
- vcuhealth.org
- Industry
- Health Care Services
Victim entity
- Name
- Virginia Commonwealth University Health System Authoritynorm: virginia commonwealth university health system authority
- Domain
- vcuhealth.org
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 2,716
- Data types
- IDENTITY_BASICHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- Multiple
- Regulator citations
- HHS OCR notified; OCR obtained assurances that the CE implemented corrective actions
- Initial access
- valid_credentials
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.