Children's Hospital Colorado
bd_f6f54a270eb5a37a · schema v1 · pii pii-v1
Full breach record for Children's Hospital Colorado →Children's Hospital Colorado reported to HHS OCR on 2020-07-27 a Hacking/IT Incident affecting 2,553 individuals, with breached information located in Email accounts. OCR investigated two related phishing incidents (2017 and 2020): one compromising an email account (3,370 individuals' PHI) due to disabled MFA, and another where workforce members granted unknown third parties access to three email accounts (10,840 individuals' PHI). OCR found HIPAA Privacy and Security Rule violations. A civil money penalty of $548,265 was imposed in 2024.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Jul 27, 2020
Filed
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Illinois State AGbd_98e5159e8e96818b2020-01-01 · +208dVerified by operator
- Illinois State AGbd_df63f008f995cb7f2020-01-01 · +208dVerified by operator
- HHS OCRbd_5a374454ce8015782017-09-08 · +1053dVerified by operator
- HHS OCR enforcementbd_daf381098a786d942024-12-05 · +1592dVerified by operator
Filing propagation · 5 filings · 2 states
View merged incident ↗Pattern: first filing Sep 8 (CO), last Dec 5 — a 2645-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.