ILPhysicalHealthcareHealthcareTheftCustomer Data InvolvedHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumResolved
Advocate Health Care Network
bd_af233c4f87dd9f88 · schema v1 · pii pii-v1
Full breach record for Advocate Health Care Network →Advocate Health Care (IL) reported to HHS OCR on 2010-01-22 a Theft affecting 812 individuals. On November 24, 2009, an Advocate nurse's laptop was stolen, containing PHI including names, addresses, dates of birth, Social Security numbers, insurance information, medications, and diagnoses. Breached information was located on a Laptop. No business associate was involved. Following the breach, Advocate revised mobile device security policies and OCR required workforce mobile-device users to submit acknowledgment forms.
HIPAA clock✓ HHS notified8 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed812 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jan 22, 2010
- Raw hash
- 925e729136439e32e7bbd368c236a8d3d9c735bf363ad1d1d09545cc6dc26392
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Advocate Health Care Networknorm: advocate health care network
- Industry
- Health Care Services
Victim entity
- Name
- Advocate Health Care Networknorm: advocate health care network
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Nov 24, 2009
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 812
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- External
- Regulator citations
- HHS OCR investigation
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Nov 24, 2009→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.