GAPhysicalHealthcareHealthcareLossCustomer Data InvolvedDelayed DiscoveryHEALTH_BASICIDENTITY_BASICHighResolved
Emory Healthcare
bd_93a3b3ade6091792 · schema v1 · pii pii-v1
Full breach record for Emory Healthcare →Emory Healthcare (GA) reported to HHS on 2012-04-18 that on February 20, 2012, ten unencrypted backup CDs containing ePHI were discovered missing. Clinical and demographic data for 315,000 surgical patients treated at three locations between September 1990 and April 2007 were affected. The CDs could only be read using decommissioned software. Breach notification was provided to HHS, affected individuals, and the media. Remediation included PHI inventory requirements and staff education. OCR obtained assurances of corrective action.
HIPAA clock✓ HHS notified8 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_3b3a896a7ff97ad2California State AGfiled 2012-05-16(28d gap)Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Apr 18, 2012
- Raw hash
- fd242968df9eae18d2a62c611e9aaed4ccf4a53ebb33aaa5e02a4600112816d9
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Emory Healthcarenorm: emory healthcare
- Domain
- emoryhealthcare.org
- Industry
- Health Care Services
Victim entity
- Name
- Emory Healthcarenorm: emory healthcare
- Domain
- emoryhealthcare.org
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Feb 20, 2012
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 315,000
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unknown
- Regulator citations
- HHS OCR — breach notification submitted; OCR obtained assurances of corrective action implementation
Compliance
- Time to disclose
- 8 weeks(58 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Feb 20, 2012→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.