WYSocial EngineeringHealthcareHealthcarePhishingCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICMediumResolved
Wyoming Medical Center
bd_954d4fcc5ee92626 · schema v1 · pii pii-v1
Full breach record for Wyoming Medical Center →On February 25, 2016, Wyoming Medical Center discovered that a hacker had compromised two employees' email accounts via phishing, exposing ePHI (names, medical record numbers, account numbers, dates of service, dates of birth, and other medical information) for 3,184 individuals. The CE notified affected individuals and media, reset email passwords, scanned systems for malware, and delivered phishing-awareness training. OCR provided technical assistance regarding ePHI safeguards for email in transit and at rest.
HIPAA clock✓ HHS notified8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed3,184 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Apr 20, 2016
- Raw hash
- d0df0b3111c15830ccf3c1942c37205278fc29e90f9990abaa3e3fa2e9c9e309
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Wyoming Medical Centernorm: wyoming medical center
Victim entity
- Name
- Wyoming Medical Centernorm: wyoming medical center
- Industry
- Healthcare Provider
- Industry
- Healthcaresource default
Incident
- Discovered
- Feb 25, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 3,184
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Phishing
- Threat actor
- External
- Regulator citations
- HHS OCR investigation; technical assistance provided
Compliance
- Time to disclose
- 8 weeks(55 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Feb 25, 2016→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.