TEXASPhysicalHealthcareHealthcareLossCustomer Data InvolvedHEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNTMediumResolved
CHRISTUS St. John Hospital
bd_b1e645f69c857f67 · schema v1 · pii pii-v1
Full breach record for CHRISTUS St. John Hospital →CHRISTUS St. John Hospital (TX) reported to HHS on 2012-11-16 a Loss affecting 5,748 individuals. On September 25, 2012, an employee lost an unsecured flash drive containing ePHI including financial, demographic, and clinical information. Breached information located on Other Portable Electronic Device. The hospital notified HHS, affected individuals, and media. Corrective actions included policy revision, encryption of storage media, and employee retraining. OCR obtained assurances of compliance.
HIPAA clock✓ HHS notified7 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed5,748 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Nov 16, 2012
- Raw hash
- f72aa5a06755dd97669a1594ea7a433be48e272bf860245b3cd65fcabb55872d
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- CHRISTUS St. John Hospitalnorm: christus st john hospital
- Industry
- Health Care Services
Victim entity
- Name
- CHRISTUS St. John Hospitalnorm: christus st john hospital
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Sep 25, 2012
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 5,748
- Data types
- HEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- Internal
- Regulator citations
- OCR obtained assurances that the CE implemented corrective actions including revised HIPAA policy, encryption of media storage devices, and retraining of involved employee.
Compliance
- Time to disclose
- 7 weeks(52 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Sep 25, 2012→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.