FEDERALHackingHealthcareHealthcareSupply Chain (3P Vendor)Business Associate (HIPAA)Employee Data InvolvedPHIHEALTH_BASICIDENTITY_BASICMediumResolved
Assurecare Risk Management, Inc.
bd_eaf33677204a6fe9 · schema v1 · pii pii-v1
Full breach record for Assurecare Risk Management, Inc. →On May 9, 2011, a computer server at Assurecare Risk Management, Inc. (a former business associate of Gypsum Management & Supply, Inc. Medical and Dental Plan) was hacked, exposing demographic, clinical, and health insurance information for 25,330 of the covered entity's current and former employees. The CE notified HHS, affected individuals, and the media. OCR confirmed a proper BA agreement was in place. Internal investigation showed little activity on the server post-hack and no reports of misuse have been received.
HIPAA clockDiscovered May 9, 2011 → Notified Jul 21, 201173d ✗ HIPAA 60-day late10 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed25,330 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jul 21, 2011
- Raw hash
- a1375cf6a778e979496b53f79b9150f9b35ae585ad289f097381d8c60e1fcf73
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Gypsum Management & Supply, Inc. Medical and Dental Plannorm: gypsum management supply inc medical and dental plan
Victim entity
- Name
- Assurecare Risk Management, Inc.norm: assurecare risk management
- Industry
- Business Associate
- Industry
- Healthcaresource default
Incident
- Discovered
- May 9, 2011
- Materiality determined
- —
- Notification sent
- Jul 21, 2011
- Affected individuals
- 25,330
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- Threat actor
- External
- Regulator citations
- HHS OCR breach report
- Third party
- via Assurecare Risk Management, Inc.BA whose server was hacked
Compliance
- Time to disclose
- 10 weeks(73 days from discovery to filing)
- Compliance flags
- HIPAA 60-day late · 73dHHS notified · 73d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: May 9, 2011→ Notified: Jul 21, 201173d 60 days HIPAA 60-day late HIPAA Discovered: May 9, 2011→ Notified: Jul 21, 201173d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.