DisclosureLens
INDIANAHackingHealthcareTechnologyHealthcareStolen CredentialsBusiness Associate (HIPAA)Customer Data InvolvedData ExfiltratedHealth (basic)Identity (basic)HighResolved

Medical Informatics Engineering, LLC

bd_c89bcf483c5d09e4 · schema v1 · pii pii-v1

Severity

High

Discovered

Jul 23, 2015

Filed

Jul 23, 2015

To disclose

Affected

3,500,000

Linked

6 filings

Confidence

96%
Full breach record for Medical Informatics Engineering, LLC2 incidents on file

Medical Informatics Engineering, Inc. (MIE), an Indiana-based business associate providing software and electronic medical record services, reported to HHS OCR on July 23, 2015 a Hacking/IT Incident affecting approximately 3,500,000 individuals. Hackers used a compromised user ID and password to access ePHI stored on Electronic Medical Records and Network Servers. OCR found MIE failed to conduct a comprehensive risk analysis prior to the breach. MIE paid a $100,000 settlement and agreed to a corrective action plan including an enterprise-wide risk analysis.

HIPAA clockDiscovered Jul 23, 2015Notified Jul 23, 20150d HHS report on time
notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.

Incident timeline

discovery → filing · ≤1 day / 0 days

Jul 23, 2015

Discovered

Jul 23, 2015

Filed

This filing is one of 6 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (5) · sorted by filing gap

Show 1 more filingup to 1400d gap

Filing propagation · 6 filings · 5 states

View merged incident ↗

Pattern: first filing Jun 23 (MA), last May 23 — a 1430-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.