FLAccidentalHealthcareHealthcareMisdeliveryCustomer Data InvolvedEmployee Data InvolvedHEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNTMediumResolved
mdINR LLC
bd_afc3b23c18c86a34 · schema v1 · pii pii-v1
Full breach record for mdINR LLC →mdINR LLC (FL) reported to HHS OCR on 2015-01-05 an Unauthorized Access/Disclosure affecting 1,859 individuals. On November 3, 2014, an IT employee sent an unsecured email with an attached spreadsheet containing PHI (patient names, billing account numbers, reporting dates, internal site codes, and facility addresses) to a manufacturer representative. Breached information was located in Email. The employee received a written warning; the CE reinforced HIPAA training and role-based access controls. OCR obtained assurances of corrective action.
HIPAA clock✓ HHS notified9 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,859 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jan 5, 2015
- Raw hash
- 20ec75f0bdebd9c748914d4129e759cf2f04e0aea8d0a280887fd6da82709d59
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- mdINR LLCnorm: mdinr
- Industry
- Health Care Services
Victim entity
- Name
- mdINR LLCnorm: mdinr
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Nov 3, 2014
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,859
- Data types
- HEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1048 Exfiltration Over Alternative Protocol
- Threat actor
- Internal
- Regulator citations
- HHS OCR — breach notification submitted; OCR obtained assurances of corrective actions implemented
- Initial access
- insider_action
Compliance
- Time to disclose
- 9 weeks(63 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Nov 3, 2014→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.