Georgia Health Sciences University
bd_bcec7c57607a7e39 · schema v1 · pii pii-v1
Full breach record for Georgia Health Sciences University →Georgia Health Sciences University reported to HHS on 2012-03-15 a Theft affecting 513 individuals. On January 19, 2012, an employee discovered her laptop was stolen from the front porch of her home. The laptop contained ePHI of 513 patients including names, dates of birth, and health data. The laptop was password-protected but not encrypted. In response, the CE encrypted all employee laptops, implemented mobile device and remote access policies, updated data backup policies, and trained staff on HIPAA policies. OCR obtained assurances that corrective actions were implemented.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 15, 2012
- Raw hash
- b9ee92f6ee62a988b65e4b2fae6230fd30fbe15a5f26a9d3c412a1f53051f1dc
Source filing
Reporting entity
- Name
- Georgia Health Sciences Universitynorm: georgia health sciences university
- Industry
- Health Care Services
Victim entity
- Name
- Georgia Health Sciences Universitynorm: georgia health sciences university
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Jan 19, 2012
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 513
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- External
- Regulator citations
- HHS OCR breach notification submittedOCR obtained assurances that corrective actions were implemented
Compliance
- Time to disclose
- 8 weeks(56 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jan 19, 2012→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.