ALPhysicalHealthcareHealthcareLossCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICLowResolved
University of Alabama at Birmingham
bd_eff2b52daee7c325 · schema v1 · pii pii-v1
Full breach record for University of Alabama at Birmingham →University of Alabama at Birmingham reported to HHS on 2017-11-27 a Loss affecting 652 individuals. Breached information located on Other Portable Electronic Device. Two unencrypted thumb drives containing PHI of 652 individuals were lost on October 25, 2017. The drives were retrieved, but it was undetermined if data was viewed. Staff were reprimanded, notifications sent, and new procedures/policies implemented to eliminate thumb drive usage for data transfer.
HIPAA clock✓ HHS notified5 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed652 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Nov 27, 2017
- Raw hash
- 6259d236b2ab8acaccdedc3c196dc23059109ed904060e10b563e354dd366b6b
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- University of Alabama at Birminghamnorm: university of alabama at birmingham
- Industry
- Health Care Services
Victim entity
- Name
- University of Alabama at Birminghamnorm: university of alabama at birmingham
- Industry
- Healthcaresource default
Incident
- Discovered
- Oct 25, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 652
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- Internal
Compliance
- Time to disclose
- 5 weeks(33 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Oct 25, 2017→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.