U.S. HealthWorks
bd_ef681d0fdf50a2d8 · schema v1 · pii pii-v1
Full breach record for U.S. HealthWorks →U.S. HealthWorks (CA) reported to HHS on 2016-09-09 a Theft affecting 1,400 individuals. On July 18, 2016, a CE-issued laptop and a notebook containing the laptop encryption password were stolen from an employee's automobile. Breached PHI included patient names, clinical information, visit dates, and SSNs for some patients. The CE notified HHS, affected individuals, and the media, offered credit monitoring for those with SSNs exposed, sanctioned the employee, and retrained staff. OCR provided Security Rule technical assistance. Breached information located on: Laptop.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Sep 9, 2016
- Raw hash
- 19e42295f114b7d489c384a474d421507a305a7bde18c6fffc347e38395654fa
Source filing
Reporting entity
- Name
- U.S. HealthWorksnorm: us healthworks
- Industry
- Health Care Services
Victim entity
- Name
- U.S. HealthWorksnorm: us healthworks
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,400
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- External
- Regulator citations
- OCR provided technical assistance regarding the Security Rule, including risk analysis and risk management.
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.