NMPhysicalHealthcareGovernmentHealthcareTheftCustomer Data InvolvedHEALTH_BASICIDENTITY_BASICLowResolved
New Mexico Department of Health
bd_cf025d550eb6c746 · schema v1 · pii pii-v1
Full breach record for New Mexico Department of Health →New Mexico Department of Health reported to HHS on 2015-12-15 a Theft affecting 561 individuals. A workforce member's laptop was stolen from her locked vehicle on October 4, 2015. The laptop contained patients' names, dates of birth, diagnoses, and medications. The CE remediated by implementing full disk encryption enterprise-wide, revising security awareness training, and procuring mobile device management and SIEM solutions. OCR obtained assurances of implementation.
HIPAA clock✓ HHS notified10 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed561 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Dec 15, 2015
- Raw hash
- 1a56563397f07c882e208795dcfbd7d427adbb600b99ea0440be25676d4468ba
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- New Mexico Department of Healthnorm: new mexico department of health
- Domain
- health.nm.gov
- Industry
- Health Care Services
Victim entity
- Name
- New Mexico Department of Healthnorm: new mexico department of health
- Domain
- health.nm.gov
- Industry
- Health Care Services
- Industry
- Healthcaresource defaultGovernmentllm
Incident
- Discovered
- Oct 4, 2015
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 561
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- External
- Regulator citations
- OCR obtained assurances from the CE that it implemented the remediation actions listed.
Compliance
- Time to disclose
- 10 weeks(72 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Oct 4, 2015→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.