John E. Gonzalez DDS
bd_a452a2bac6d329e4 · schema v1 · pii pii-v1
Full breach record for John E. Gonzalez DDS →On July 25, 2016, a thief broke Dr. John E. Gonzalez DDS's car window and stole a briefcase containing an unencrypted external hard drive with ePHI for approximately 1,025 patients. Exposed data included SSNs, dates of birth, phone numbers, physical/email addresses, health insurance information, and dental images with patient names. The practice notified HHS, affected individuals, and the media, and subsequently acquired an encrypted hard drive. OCR provided technical assistance on breach notification and Security Rule risk management. Submitted to HHS OCR on 2016-08-14. Breached information located on an Other Portable Electronic Device.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_0b33814121b3e3b0California State AGfiled 2016-08-14Verified by operator
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Aug 14, 2016
- Raw hash
- 66e4b77a89e1841dd7a365b9d6da0f16855796a8c5626ef502983783f8d766f6
Source filing
Reporting entity
- Name
- John E. Gonzalez DDSnorm: john e gonzalez dds
- Industry
- Health Care Services
Victim entity
- Name
- John E. Gonzalez DDSnorm: john e gonzalez dds
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Jul 25, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,025
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- External
- Regulator citations
- HHS OCR notified; technical assistance provided on breach notification and Security Rule risk analysis and risk management provisions
Compliance
- Time to disclose
- 20 days(20 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jul 25, 2016→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.