KYAccidentalHealthcareHealthcareMisdeliveryCustomer Data InvolvedHEALTH_BASICIDENTITY_BASICLowResolved
Summit Medical Group, Inc.
bd_c123bba0c60666c9 · schema v1 · pii pii-v1
Full breach record for Summit Medical Group, Inc. →Summit Medical Group, Inc. dba St. Elizabeth Physicians (KY) reported to HHS on 2016-08-23 an Unauthorized Access/Disclosure affecting 674 individuals. On July 12, 2016, a Weight Management Center employee sent a mass email about a vitamin presentation without blind-copying recipients, exposing all recipient email addresses. The CE adjusted emailing procedures, sanctioned the employee, and provided workforce training. OCR investigated and obtained assurances of corrective action. Breached information located in Email.
HIPAA clockDiscovered Jul 12, 2016 → Notified Aug 23, 201642d ✓ HIPAA 60-day OK6 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed674 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Aug 23, 2016
- Raw hash
- e596688205bf95a63e4c8fe8e54017f17dbc76605802c937c7e53409d018dab6
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Summit Medical Group, Inc.norm: summit medical
- Industry
- Health Care Services
Victim entity
- Name
- Summit Medical Group, Inc.norm: summit medical
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Jul 12, 2016
- Materiality determined
- —
- Notification sent
- Aug 23, 2016
- Affected individuals
- 674
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- Threat actor
- Internal
- Regulator citations
- HHS OCR investigation; OCR obtained assurances of corrective action implementation
- Initial access
- insider_action
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- HIPAA 60-day OK · 42dHHS notified · 42d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jul 12, 2016→ Notified: Aug 23, 201642d 60 days HIPAA 60-day OK HIPAA Discovered: Jul 12, 2016→ Notified: Aug 23, 201642d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.