Barnabas Health Medical Group, P.C.
bd_c4754ebdeacec78c · schema v1 · pii pii-v1
Full breach record for Barnabas Health Medical Group, P.C. →Barnabas Health Medical Group, P.C. (NJ) reported to HHS OCR on 2013-11-05 a Theft affecting 1,100 individuals. An unencrypted laptop used to conduct spirometry tests was stolen from a CE office during business hours. PHI involved included demographic and clinical information. The CE notified HHS, media, and affected individuals; reported the theft to law enforcement; conducted an internal investigation and on-site office reviews; retrained staff; and replaced the spirometer. OCR obtained corrective action assurances and initiated further remediation requirements.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Nov 5, 2013
- Raw hash
- 937d24a3253d51e6abcd850552b47a3dfcecaab90715263436ecba6a6c2fc963
Source filing
Reporting entity
- Name
- Barnabas Health Medical Group, P.C.norm: barnabas health medical
- Industry
- Health Care Services
Victim entity
- Name
- Barnabas Health Medical Group, P.C.norm: barnabas health medical
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,100
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- External
- Regulator citations
- HHS OCR investigation; corrective action plan obtained; CE required to conduct risk analysis, implement remediation plan, implement policies for biomedical devices containing ePHI, and regularly review information system activity records.
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.