Quanterion Solutions Inc
bd_c7b9b6bd3cef09eb · schema v1 · pii pii-v1
Full breach record for Quanterion Solutions Inc →Quanterion Solutions, Inc. (a business associate) reported to HHS on 2012-11-01 a Theft affecting 1,017 individuals. An unencrypted thumb drive containing ePHI was stolen by an employee of the BA. ePHI included names, addresses, dates of birth, driver's license numbers, SSNs, claims info, clinical info, diagnosis/conditions, lab results, treatment info, and medications. The covered entity (Surgical Associates of Utica, PC) filed a police report; the employee was arrested. Breach notifications were sent to HHS, media, and affected individuals; credit monitoring was provided. OCR's investigation led the CE to execute a BA agreement. Breached information located on Network Server (thumb drive).
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Nov 1, 2012
- Raw hash
- e2e80cd21b4343a6d6d12c86459e1743849c54abae90fd1533acec0a5d0a7472
Source filing
Reporting entity
- Name
- Quanterion Solutions Incnorm: quanterion solutions
- Industry
- Business Associate
Victim entity
- Name
- Quanterion Solutions Incnorm: quanterion solutions
- Industry
- Business Associate
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,017
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- Internal
- Regulator citations
- HHS OCR investigation; CE executed BA agreement as a result
- Third party
- via Quanterion Solutions, Inc.business associate
- Initial access
- insider_action
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.