FEDERALHackingHealthcareHealthcareVulnerability ExploitMisconfigurationBusiness Associate (HIPAA)Customer Data InvolvedPatch Available Not AppliedHEALTH_BASICIDENTITY_BASICMediumResolved
Tandigm Health
bd_d4ae16e6ea363fda · schema v1 · pii pii-v1
Full breach record for Tandigm Health →Tandigm Health (PA) reported to HHS on 2018-11-21 a Hacking/IT Incident affecting 7,376 individuals. A vulnerability on the covered entity's website allowed unauthorized individuals to bypass security safeguards and potentially access a network server database containing PHI, including demographic and clinical information. The CE immediately fixed the misconfiguration, tested and validated its security configuration, and notified HHS, affected individuals, and the media. OCR reviewed the CE's policies for Security Rule compliance.
HIPAA clock✓ HHS notified
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_3d5ba1a822785137Montana State AGfiled 2018-11-21Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Nov 21, 2018
- Raw hash
- ba9541e651cdc48573532d323b0bfe4d3f9ddba80cb4e214a65fd1a5b82d8789
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Tandigm Healthnorm: tandigm health
Victim entity
- Name
- Tandigm Healthnorm: tandigm health
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 7,376
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- OCR reviewed covered entity's policies for compliance with the Security Rule
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.