Recovery Institute of the South East P.A.
bd_acb4c122a7f93476 · schema v1 · pii pii-v1
Full breach record for Recovery Institute of the South East P.A. →Recovery Institute of the South East P.A. (FL) reported to HHS OCR on 2017-10-21 a Hacking/IT Incident allegedly affecting 689 individuals, spanning Desktop Computer, EMR, Email, Laptop, Network Server, and other media. The report alleged a former employee remotely accessed computers without authorization (Dec 2016–Oct 2017). A forensic investigation by Envista Forensics found no evidence of malware, unauthorized access, or data exfiltration; PHI was not exposed. OCR found inadequate HIPAA policies and provided technical assistance; the CE implemented corrective actions.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 1, 2016
Begins
Oct 21, 2017
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.