FEDERALHackingHealthcareHealthcareBusiness Associate (HIPAA)Customer Data InvolvedPHIIDENTITY_BASICHEALTH_BASICBIOMETRICMediumResolved
Atchison Hospital Association
bd_ba69afead34e363c · schema v1 · pii pii-v1
Full breach record for Atchison Hospital Association →Atchison Hospital Association reported to HHS on April 11, 2018, a hacking incident affecting 667 individuals. The breach occurred when a third party hacked into a web server belonging to a business associate, Fast Health Corporation, between August 14, 2017, and August 18, 2017. The compromised protected health information included names, dates of birth, and photographs. In response, the hospital terminated its relationship with the business associate and updated its breach notification policies.
HIPAA clock✓ HHS notified8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed667 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Apr 11, 2018
- Raw hash
- f494fbd755cb85e25e346514ffab43e600ab1adb04b283e0b663954d3f5f1694
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Atchison Hospital Associationnorm: atchison hospital
- Industry
- Health Care Services
Victim entity
- Name
- Atchison Hospital Associationnorm: atchison hospital
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Feb 14, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 667
- Data types
- PHIIDENTITY_BASICHEALTH_BASICBIOMETRIC
- Attack vector
- Unauthorized Access
- Threat actor
- Partner
- Regulator citations
- The CE provided breach notification to HHS, affected individuals, and the media.As a result of OCR’s investigation, the CE updated its Breach Rule Notification policy and trained staff on its updated policy.OCR obtained documented assurances that the CE implemented the corrective action steps listed above.
Compliance
- Time to disclose
- 8 weeks(56 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Feb 14, 2018→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.