Johns Hopkins University Applied Physics Laboratory (JHU/APL) Medical and Dental Insurance Plan
bd_e7f5aabe69c4d259 · schema v1 · pii pii-v1
Full breach record for Johns Hopkins University Applied Physics Laboratory (JHU/APL) Medical and Dental Insurance Plan →A benefits staff member at JHU/APL Medical and Dental Insurance Plan accidentally attached a file containing PHI to an email sent to 85 employees. The email included names, dates of birth, Social Security numbers, and marital and disability status of approximately 692 individuals. All recipients were notified within 5 days and the email was deleted. Following an OCR investigation, the covered entity updated policies requiring peer review of bulk benefit emails, mandated PHI email encryption, took personnel action against the responsible employee, and committed to additional HIPAA and encryption training. Location of breached information: Other.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Oct 6, 2010
- Raw hash
- 8214d4a0e980cb38f600767b9530aec709bcb2c829f90053d5b494c95c446dc7
Source filing
Reporting entity
- Name
- Johns Hopkins University Applied Physics Laboratory (JHU/APL) Medical and Dental Insurance Plannorm: johns hopkins university applied physics laboratory jhu apl medical and dental insurance plan
- Industry
- Insurance — Health
Victim entity
- Name
- Johns Hopkins University Applied Physics Laboratory (JHU/APL) Medical and Dental Insurance Plannorm: johns hopkins university applied physics laboratory jhu apl medical and dental insurance plan
- Industry
- Insurance — Health
- Industry
- Healthcaresource defaultFinancial Servicesllm
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 692
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unknown
- Threat actor
- Internal
- Regulator citations
- HHS OCR investigation conducted; covered entity updated policies and procedures following OCR investigation
- Initial access
- insider_action
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.