DisclosureLens
FLORIDAMisuseHealthcareHealthcarePrivilege AbuseCustomer Data InvolvedDelayed DiscoveryHealth (basic)Identity (basic)LowResolved

Recovery Institute of the South East P.A.

bd_acb4c122a7f93476 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Oct 21, 2017

To disclose

Affected

689

Confidence

93%
Full breach record for Recovery Institute of the South East P.A.

Recovery Institute of the South East P.A. (FL) reported to HHS OCR on 2017-10-21 a Hacking/IT Incident allegedly affecting 689 individuals, spanning Desktop Computer, EMR, Email, Laptop, Network Server, and other media. The report alleged a former employee remotely accessed computers without authorization (Dec 2016–Oct 2017). A forensic investigation by Envista Forensics found no evidence of malware, unauthorized access, or data exfiltration; PHI was not exposed. OCR found inadequate HIPAA policies and provided technical assistance; the CE implemented corrective actions.

HIPAA clock HHS notified
no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.

Incident timeline

Dec 1, 2016

Begins

Oct 21, 2017

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed689 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.