INDIANAPhysicalHealthcareHealthcareTheftBusiness Associate (HIPAA)Customer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICMediumResolved
Gibson
bd_9bd2599812739aee · schema v1 · pii pii-v1
Full breach record for Gibson →Gibson Insurance Agency, Inc. reported to HHS on 2016-10-14 a Theft affecting 7242 individuals. Breached information located on Laptop. An employee's laptop was stolen from her car on July 28, 2016, potentially containing demographic and health insurance information. The covered entity notified HHS, individuals, and media, investigated, sanctioned the employee, and implemented safeguards including encryption, security management systems, complex passwords, and automatic logoff.
HIPAA clock✓ HHS notified11 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_5cc94d05fc3ce36dMontana State AGfiled 2016-10-14Candidate
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Oct 14, 2016
- Raw hash
- 37fef962e63fa6eb285b0188adc7973b51448354d45d5da6e416b52af5fb8176
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Gibsonnorm: gibson
- Domain
- gibson.com
- Industry
- Business Associate
Victim entity
- Name
- Gibsonnorm: gibson
- Domain
- gibson.com
- Industry
- Healthcaresource default
Incident
- Discovered
- Jul 28, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 7,242
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- Internal
- Third party
- via Gibson Insurance Agency, Inc.business associate
Compliance
- Time to disclose
- 11 weeks(78 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jul 28, 2016→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.