DisclosureLens
INDIANAMalwareHealthcareHealthcareBusiness Associate (HIPAA)Customer Data InvolvedSupply Chain (3P Vendor)Health (basic)Identity (basic)MediumResolved

Lafayette Pain Care PC

bd_d523600f8401a017 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

May 9, 2016

To disclose

Affected

7,500

Confidence

94%
Full breach record for Lafayette Pain Care PC

Lafayette Pain Care PC (IN) reported to HHS OCR on 2016-05-09 a Hacking/IT Incident affecting 7,500 individuals. Malware infected business associate Bizmatics, Inc., enabling unauthorized access to PHI stored on network servers in 2015. Exposed data included diagnoses/conditions, lab results, medications, and other treatment information. The CE notified HHS, affected individuals, and media; provided substitute notice; established a call center; and offered one year of free credit monitoring. A new BA agreement with Bizmatics was executed and OCR obtained documented assurances of corrective action.

HIPAA clock HHS notified
no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.

Incident timeline

Jan 1, 2015

Begins

May 9, 2016

Filed

Part of Bizmatics supply-chain incident (2016) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed7,500 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.