Myriad Genetic Laboratories, Inc.
bd_c67d00bde54125bf · schema v1 · pii pii-v1
Full breach record for Myriad Genetic Laboratories, Inc. →An employee of Myriad Genetic Laboratories, Inc. (UT) emailed unsecured PHI to his personal email account for job-convenience purposes. The PHI of 643 individuals included names, dates of birth, addresses, physicians' names, genetic test results, test IDs, family and personal medical histories, and family pedigree information. The CE notified HHS and affected individuals, posted substitute notice, and offered one year of free identity theft protection. Post-breach, the CE revised email encryption procedures, retrained the employee, and received OCR technical assistance on Security Rule risk analysis. Submitted to HHS OCR on 2014-03-29.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 29, 2014
- Raw hash
- 765d6c7e5ece08fc87bd51c1888ccba328521e718e12371ad064d2dfb38160d7
Source filing
Reporting entity
- Name
- Myriad Genetic Laboratories, Inc.norm: myriad genetic laboratories
- Domain
- myriad.com
- Industry
- Health Care Services
Victim entity
- Name
- Myriad Genetic Laboratories, Inc.norm: myriad genetic laboratories
- Domain
- myriad.com
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 643
- Data types
- IDENTITY_BASICHEALTH_BASICHEALTH_GENETIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1048 Exfiltration Over Alternative Protocol
- Threat actor
- Internal
- Regulator citations
- OCR provided technical assistance regarding risk analysis and risk management requirements of the Security Rule
- Initial access
- insider_action
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.