DisclosureLens
AccidentalHealthcareTechnologyHealthcareMisdeliveryData ExfiltratedCustomer Data InvolvedPIIPHIIdentity (basic)Government IDHealth (basic)CredentialsMediumContained

Catholic Health Services

bd_03cf6c0548a9c6d3 · schema v1 · pii pii-v2

Severity

Medium

Discovered

Nov 15, 2024

Filed

May 9, 2025

To disclose

Affected

10state residents only

Confidence

66%
Full breach record for Catholic Health Services

Serviceaide, Inc. notified Nebraska AG that patient information from Catholic Health was inadvertently made publicly available between Sept 19 and Nov 5, 2024. Serviceaide discovered the misconfiguration on Nov 15, 2024, secured the database, and engaged a vendor to review data. Approximately 10 Nebraska residents were notified on May 9, 2025. Data included names, SSNs, DOBs, medical records, and credentials. No evidence of copying was found, but exfiltration could not be ruled out. Credit monitoring was offered.

Incident timeline

undetected · 57 days

Sep 19, 2024

Begins

Nov 15, 2024

Discovered

May 9, 2025

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed10 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.