DisclosureLens
TENNESSEEPhysicalHealthcareHealthcareTheftCustomer Data InvolvedPHIPIIIdentity (basic)Government IDHealth (basic)HighResolved

Roark's Pharmacy

bd_aab70f5eb418f3ba · schema v1 · pii pii-v1

Severity

High

Discovered

Jan 13, 2016

Filed

Feb 19, 2016

To disclose

5 weeks

Affected

3,000

Confidence

95%
Full breach record for Roark's Pharmacy

Roark's Pharmacy (TN) reported to HHS OCR that on January 13, 2016 its facility was broken into and computer hard drives containing PHI of approximately 3,000 individuals were stolen. PHI included names, DOBs, addresses, diagnoses, conditions, medications, health insurance information, and SSNs (where used as insurance ID). The CE notified HHS and affected individuals. OCR provided technical assistance and resource materials. The CE strengthened physical security (metal gate, improved alarm, securing sensitive equipment).

HIPAA clockDiscovered Jan 13, 2016Notified Feb 19, 201637d HHS report on time5 weeks discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

discovery → filing · 5 weeks / 37 days

Jan 13, 2016

Discovered

Feb 19, 2016

Filed

vs. sector median

6 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed3,000 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.