INDIANAHackingHealthcareTechnologyHealthcareStolen CredentialsBusiness Associate (HIPAA)Customer Data InvolvedData ExfiltratedHEALTH_BASICIDENTITY_BASICHighResolved
Medical Informatics Engineering, LLC
bd_c89bcf483c5d09e4 · schema v1 · pii pii-v1
Full breach record for Medical Informatics Engineering, LLC →Medical Informatics Engineering, Inc. (MIE), an Indiana-based business associate providing software and electronic medical record services, reported to HHS OCR on July 23, 2015 a Hacking/IT Incident affecting approximately 3,500,000 individuals. Hackers used a compromised user ID and password to access ePHI stored on Electronic Medical Records and Network Servers. OCR found MIE failed to conduct a comprehensive risk analysis prior to the breach. MIE paid a $100,000 settlement and agreed to a corrective action plan including an enterprise-wide risk analysis.
HIPAA clockDiscovered Jul 23, 2015 → Notified Jul 23, 20150d ✓ HIPAA 60-day OK≤1 day discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed3,500,000 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jul 23, 2015
- Raw hash
- 8a8e0602d0fc9ae750983bdeb1a622af17225f89b166a5eef8e82304e6a989b9
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Medical Informatics Engineering, LLCnorm: medical informatics engineering
- Domain
- mieweb.com
- Industry
- Business Associate
Victim entity
- Name
- Medical Informatics Engineering, LLCnorm: medical informatics engineering
- Domain
- mieweb.com
- Industry
- Business Associate
- Industry
- Healthcaresource defaultTechnologyllm
Incident
- Discovered
- Jul 23, 2015
- Materiality determined
- —
- Notification sent
- Jul 23, 2015
- Affected individuals
- 3,500,000
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- HHS OCR investigation$100,000 settlement payment to HHS OCRCorrective Action Plan including enterprise-wide risk analysis
- Initial access
- valid_credentials
Compliance
- Time to disclose
- ≤1 day(0 days from discovery to filing)
- Compliance flags
- HIPAA 60-day OK · 0dHHS notified · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jul 23, 2015→ Notified: Jul 23, 20150d 60 days HIPAA 60-day OK HIPAA Discovered: Jul 23, 2015→ Notified: Jul 23, 20150d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.