ILAccidentalHealthcareHealthcareMisdeliveryBusiness Associate (HIPAA)Customer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICLowResolved
Midwest Orthopedic Consultants
bd_cba36b7defd8aafd · schema v1 · pii pii-v1
Full breach record for Midwest Orthopedic Consultants →Midwest Orthopaedic Center SC reported to HHS on 2014-07-23 a Unauthorized Access/Disclosure affecting 680 individuals. Breached information located on Network Server. A former business associate, McKesson Corporation, unintentionally made patient records accessible on the Internet via Google search between Dec 1, 2013 and Apr 17, 2014. Data was destroyed, caches purged, and credit monitoring offered.
HIPAA clock✓ HHS notified33 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed680 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jul 23, 2014
- Raw hash
- 2133dcbd46fb63e734aede0cc9ca7a36180c7238d62f9dfba76c1400e320dca1
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Midwest Orthopedic Consultantsnorm: midwest orthopedic consultants
- Domain
- orthoexperts.com
- Industry
- Health Care Services
Victim entity
- Name
- Midwest Orthopedic Consultantsnorm: midwest orthopedic consultants
- Domain
- orthoexperts.com
- Industry
- Healthcaresource default
Incident
- Discovered
- Dec 1, 2013
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 680
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1530 Data from Cloud Storage Object
- Threat actor
- Internal
- Regulator citations
- Notified HHSOCR obtained written assurances that the CE and BA implemented the corrective actions
- Third party
- via McKesson Corporationbusiness associate
Compliance
- Time to disclose
- 33 weeks(234 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Dec 1, 2013→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.