Mississippi State Department of Health
bd_e509afb625f9facf · schema v1 · pii pii-v1
Full breach record for Mississippi State Department of Health →Mississippi State Department of Health reported to HHS on 2018-03-26 an Unauthorized Access/Disclosure affecting 30,799 individuals. On January 25, 2018, an employee accidentally emailed an unencrypted spreadsheet containing PHI (names, ID numbers, dates of birth, SSNs, and STD lab results) to external contractors on a joint project. Contractors confirmed they did not retain or share the PHI. The CE sanctioned responsible employees, provided onsite HIPAA training, and issued timely notifications to HHS, individuals, and media. OCR obtained assurances of corrective actions.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 26, 2018
- Raw hash
- 2b1fdfba14022bdc4dd5399d27ffdd3470ec599dbcb6209b5d2363bd446f484f
Source filing
Reporting entity
- Name
- Mississippi State Department of Healthnorm: mississippi state department of health
- Industry
- Health Care Services
Victim entity
- Name
- Mississippi State Department of Healthnorm: mississippi state department of health
- Industry
- Health Care Services
- Industry
- Healthcaresource defaultGovernmentllm
Incident
- Discovered
- Jan 25, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 30,799
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1048 Exfiltration Over Alternative Protocol
- Threat actor
- Internal
- Regulator citations
- OCR obtained assurances that the CE implemented corrective actions and performed its notification obligations.
- Initial access
- insider_action
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jan 25, 2018→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.