Lafayette Pain Care PC
bd_d523600f8401a017 · schema v1 · pii pii-v1
Full breach record for Lafayette Pain Care PC →Lafayette Pain Care PC (IN) reported to HHS OCR on 2016-05-09 a Hacking/IT Incident affecting 7,500 individuals. Malware infected business associate Bizmatics, Inc., enabling unauthorized access to PHI stored on network servers in 2015. Exposed data included diagnoses/conditions, lab results, medications, and other treatment information. The CE notified HHS, affected individuals, and media; provided substitute notice; established a call center; and offered one year of free credit monitoring. A new BA agreement with Bizmatics was executed and OCR obtained documented assurances of corrective action.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 1, 2015
Begins
May 9, 2016
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.