DisclosureLens
CALIFORNIAPhysicalHealthcareHealthcareTheftCustomer Data InvolvedHealth (basic)Identity (basic)Government IDHighResolved

U.S. HealthWorks

bd_ef681d0fdf50a2d8 · schema v1 · pii pii-v1

Severity

High

Discovered

Filed

Sep 9, 2016

To disclose

Affected

1,400

Confidence

98%
Full breach record for U.S. HealthWorks3 incidents on file

U.S. HealthWorks (CA) reported to HHS on 2016-09-09 a Theft affecting 1,400 individuals. On July 18, 2016, a CE-issued laptop and a notebook containing the laptop encryption password were stolen from an employee's automobile. Breached PHI included patient names, clinical information, visit dates, and SSNs for some patients. The CE notified HHS, affected individuals, and the media, offered credit monitoring for those with SSNs exposed, sanctioned the employee, and retrained staff. OCR provided Security Rule technical assistance. Breached information located on: Laptop.

HIPAA clock HHS notified
no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.

Incident timeline

Jul 18, 2016

Begins

Sep 9, 2016

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,400 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.