Buffalo Heart Group
bd_ad30cd33a6fc8ece · schema v1 · pii pii-v1
Full breach record for Buffalo Heart Group →Buffalo Heart Group (NY) reported to HHS OCR on 2015-05-28 an Unauthorized Access/Disclosure breach affecting 567 individuals. A staff physician shared her password with a third party, who then remotely accessed the covered entity's EMR system. Breached ePHI included names, dates of birth, addresses, demographic and clinical information. OCR investigated and provided substantial technical assistance, requiring the CE to implement a risk analysis, risk management plan, security training, audit controls, and regular activity reviews.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
May 28, 2015
Filed
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.