<?xml version="1.0" encoding="UTF-8"?>
<incident>
  <arrest type="boolean">false</arrest>
  <breach-type-id type="integer">10</breach-type-id>
  <comments-count type="integer">1</comments-count>
  <data-family-id type="integer">1</data-family-id>
  <data-recovered type="boolean">false</data-recovered>
  <disputed type="boolean">false</disputed>
  <fringe type="boolean">false</fringe>
  <fringe-description nil="true"></fringe-description>
  <id type="integer">207</id>
  <lawsuit type="boolean">true</lawsuit>
  <records type="integer">365000</records>
  <submission-id type="integer" nil="true"></submission-id>
  <updated-at type="datetime">2008-07-09T22:43:21Z</updated-at>
  <user-id type="integer" nil="true"></user-id>
  <breach-types type="array">
    <breach_type>
      <name>Stolen Tape</name>
    </breach_type>
  </breach-types>
  <data-types type="array">
    <data_type>
      <short_name>NAA</short_name>
    </data_type>
    <data_type>
      <short_name>MED</short_name>
    </data_type>
  </data-types>
  <timeline-items type="array">
    <timeline_item>
      <first_date>2006-01-26 00:00:00 UTC</first_date>
      <type>Organization reports incident</type>
    </timeline_item>
  </timeline-items>
  <vector>
    <name>Outside</name>
  </vector>
  <primary-organization>
    <business-type-id type="integer">4</business-type-id>
    <freebase-cached-data type="yaml" nil="true"></freebase-cached-data>
    <freebase-description>Providence Health &amp; Services is a not-for-profit Catholic health care ministry that includes 27 hospitals, more than 35 non-acute facilities and numerous other health, housing and educational services in the states of Alaska, Washington, Montana, Oregon and California on the United States west coast. Headquartered in Renton, Washington, the health system is sponsored by the Sisters of Providence (Montreal, Quebec) religious community in Alaska, Washington, Montana and Oregon. In southern California, the health system is co-sponsored by the Sisters of Providence and the Sisters of the Little Company of Mary.
Providence Health System was established by the Sisters of Providence (Montreal, Quebec), a community of Roman Catholic sisters founded in Montreal, Quebec by Mother &#201;milie Gamelin...</freebase-description>
    <freebase-pref-name>Providence Health System</freebase-pref-name>
    <id type="integer">209</id>
    <is-private type="boolean">false</is-private>
    <name>Providence Health System</name>
    <stock-symbol></stock-symbol>
    <updated-at type="datetime">2011-06-28T21:16:42Z</updated-at>
  </primary-organization>
  <secondary-organizations type="array"/>
  <summary>
    <summary>Personal data and medical records for 365,000 on stolen backup disks and tapes</summary>
  </summary>
  <comments type="array">
    <comment>
      <content>This case had a lot of follow-up, in addition to the settlement with the Oregon AG (that file available on OSF already):

- The U.S. Dept. of Health &amp; Human Services/Office of Civil Rights issued its first financial penalty ever for violating HIPAA.  See http://www.hhs.gov/news/press/2008pres/07/20080717a.html of July, 2008. The settlement required Providence to implement even more security and corrective measures.

- A class action lawsuit filed against Providence was thrown out of court in 2007.

- Steven Shields, the IT worker who reported the data theft to law enforcement, was fired and subsequently filed a wrongful termination suit under Oregon's whistleblower statute.  I  don't know the status of that, but defending the lawsuit certainly adds to Providence's costs of this one breach.

/Dissent
 http://www.phiprivacy.net</content>
      <created_at>2009-01-19 10:24:41 UTC</created_at>
    </comment>
  </comments>
  <location>
    <address>USA</address>
    <thoroughfare_name></thoroughfare_name>
    <dependent_locality_name></dependent_locality_name>
    <locality_name></locality_name>
    <sub_administrative_area_name></sub_administrative_area_name>
    <administrative_area_name></administrative_area_name>
    <postal_code_number></postal_code_number>
    <country_name_code>US</country_name_code>
    <longitude>37.0902</longitude>
    <latitude>-95.7129</latitude>
    <accuracy>1</accuracy>
  </location>
</incident>

