DisclosureLens
PhysicalHealthcareProfessional ServicesHealthcareTheftCustomer Data InvolvedData ExfiltratedIdentity (basic)Government IDHealth (basic)Financial accountHighContained

Indiana State Medical Association

bd_c5ca7ff1ad265c5c · schema v1 · pii pii-v1

Severity

High

Discovered

Feb 13, 2015

Filed

Mar 6, 2015

To disclose

21 days

Affected · nationwide

39,0905 in this filing

Linked

2 filings

Confidence

66%
Full breach record for Indiana State Medical Association

Indiana State Medical Association (ISMA) reported the theft of two unencrypted archive hard drives containing personal information of 39,090 individuals. The theft occurred on February 13, 2015, while an employee was transporting the drives to an off-site storage location. Affected data included names, addresses, dates of birth, email addresses, health plan numbers, and for some individuals, social security numbers and medical history. ISMA discovered the theft the same day and reported it to police. Encryption had been disabled by an IT vendor without ISMA's knowledge. ISMA restored encryption, revised policies, and offered one year of credit monitoring.

Incident timeline

discovery → filing · 21 days

Feb 13, 2015

Begins

Feb 13, 2015

Discovered

Mar 6, 2015

Filed

vs. sector median

9 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
HHS OCRMar 6 · first
New Hampshire State AGMar 6 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.