Emory Healthcare
bd_93a3b3ade6091792 · schema v1 · pii pii-v1
Full breach record for Emory Healthcare →4 incidents on fileEmory Healthcare (GA) reported to HHS on 2012-04-18 that on February 20, 2012, ten unencrypted backup CDs containing ePHI were discovered missing. Clinical and demographic data for 315,000 surgical patients treated at three locations between September 1990 and April 2007 were affected. The CDs could only be read using decommissioned software. Breach notification was provided to HHS, affected individuals, and the media. Remediation included PHI inventory requirements and staff education. OCR obtained assurances of corrective action.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 20, 2012
Begins
Feb 20, 2012
Discovered
Apr 18, 2012
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- California State AGbd_3b3a896a7ff97ad22012-05-16 · +28dVerified
Filing propagation · 2 filings · 2 states
View merged incident ↗Pattern: first filing Apr 18 (GA), last May 16 (CA) — a 28-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.