DisclosureLens
NORTH CAROLINASocial EngineeringHealthcareHealthcarePhishingStolen CredentialsCustomer Data InvolvedIdentity (basic)Government IDHealth (basic)HighResolved

ABB Optical Group

bd_984f8f7ece6e466f · schema v1 · pii pii-v1

Severity

High

Discovered

Aug 25, 2017

Filed

Sep 11, 2017

To disclose

17 days

Affected

28,012

Confidence

97%
Full breach record for ABB Optical Group

ABB, Inc. (NC) reported to HHS on 2017-09-11 a Hacking/IT Incident affecting 28,012 individuals. On August 25, 2017, four employees of ABB, Inc.'s health plan were victims of an email phishing scheme, potentially exposing names, dates of birth, addresses, Social Security numbers, and insurance member ID numbers of 28,017 individuals. The CE strengthened its email security measures and technical policies. OCR obtained assurances that corrective actions were implemented. Breached information was located on Email systems.

HIPAA clock HHS report on time17 days discovery → filing
occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.

Incident timeline

discovery → filing · 17 days

Aug 25, 2017

Begins

Aug 25, 2017

Discovered

Sep 11, 2017

Filed

vs. sector median

9 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed28,012 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.