Veterans Health Administration
bd_d1624483c59e53a5 · schema v1 · pii pii-v1
Full breach record for Veterans Health Administration →Veterans Health Administration (VHA) reported to HHS on 2018-11-06 an Unauthorized Access/Disclosure affecting 19,254 individuals. On August 8 and September 4, 2018, business associate Xerox Corporation erroneously printed appointment reminder cards for patients that were mailed to another patient, exposing demographic and clinical information. The BA implemented additional controls including joint CE/BA template review and a match alert notification. OCR reviewed the BA agreement, notification letters, and security measures, and obtained assurances of corrective action.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Nov 6, 2018
- Raw hash
- 4b37170e66fd48ec73b25c0cc6b645eee162cc65d33f80a41fb2d4328a2d0768
Source filing
Reporting entity
- Name
- Veterans Health Administrationnorm: veterans health administration
- Domain
- va.gov
- Industry
- Health Care Services
Victim entity
- Name
- Veterans Health Administrationnorm: veterans health administration
- Domain
- va.gov
- Industry
- Health Care Services
- Industry
- Healthcaresource defaultGovernmentllm
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 19,254
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access· Xerox Corporation
- Threat actor
- Partner
- Regulator citations
- OCR reviewed BA agreementOCR reviewed individual breach notification letterOCR reviewed security measures implementedOCR obtained assurances of corrective action implementation
- Third party
- via Xerox Corporation
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.