TNPhysicalHealthcareHealthcareTheftCustomer Data InvolvedPHIPIIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICHighResolved
Roark's Pharmacy
bd_aab70f5eb418f3ba · schema v1 · pii pii-v1
Full breach record for Roark's Pharmacy →Roark's Pharmacy (TN) reported to HHS OCR that on January 13, 2016 its facility was broken into and computer hard drives containing PHI of approximately 3,000 individuals were stolen. PHI included names, DOBs, addresses, diagnoses, conditions, medications, health insurance information, and SSNs (where used as insurance ID). The CE notified HHS and affected individuals. OCR provided technical assistance and resource materials. The CE strengthened physical security (metal gate, improved alarm, securing sensitive equipment).
HIPAA clockDiscovered Jan 13, 2016 → Notified Feb 19, 201637d ✓ HIPAA 60-day OK5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed3,000 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Feb 19, 2016
- Raw hash
- 86d5e1e19250e632ce832448e6ab3ff871c482e804c04c0cb060c949358961d1
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Roark's Pharmacynorm: roark s pharmacy
Victim entity
- Name
- Roark's Pharmacynorm: roark s pharmacy
- Industry
- Healthcare Provider
- Industry
- Healthcaresource default
Incident
- Discovered
- Jan 13, 2016
- Materiality determined
- —
- Notification sent
- Feb 19, 2016
- Affected individuals
- 3,000
- Data types
- PHIPIIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unknown
- Threat actor
- ExternalFinancial
- Regulator citations
- OCR provided technical assistance regarding the Breach Notification Rule and impermissible disclosuresOCR provided resource materials regarding small businesses and the Privacy and Security RulesOCR obtained assurances that corrective actions were implemented
Compliance
- Time to disclose
- 5 weeks(37 days from discovery to filing)
- Compliance flags
- HIPAA 60-day OK · 37dHHS notified · 37d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jan 13, 2016→ Notified: Feb 19, 201637d 60 days HIPAA 60-day OK HIPAA Discovered: Jan 13, 2016→ Notified: Feb 19, 201637d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.