DisclosureLens
MISSOURIHackingHealthcareHealthcareStolen CredentialsBusiness Associate (HIPAA)Customer Data InvolvedData ExfiltratedPHIHealth (basic)Identity (basic)Government IDHighContained

Sheet Metal Local 36 Welfare Fund

bd_e790caafabf7d87c · schema v1 · pii pii-v1

Severity

High

Discovered

Filed

Jul 15, 2013

To disclose

Affected

4,560

Confidence

67%

Sheet Metal Local 36 Welfare Fund reported to HHS on 2013-07-15 a Unauthorized Access/Disclosure affecting 4560 individuals. Breached information located on Other. A business associate employee inadvertently uploaded Excel spreadsheets containing PHI (names, addresses, DOB, SSN) to an unsecure website. An unknown entity in China accessed and exfiltrated the data. The business associate, People Resources Corporation, removed the data and implemented additional security controls.

HIPAA clock HHS notified
no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.

Incident timeline — partial

? — ?

Breach window unknown

Jul 15, 2013

Filed

No filing yet · watching

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed4,560 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.