INDIANASocial EngineeringHealthcareHealthcarePhishingStolen CredentialsCustomer Data InvolvedHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTHighResolved
St. Mary's Health
bd_05b7228841867ac2 · schema v1 · pii pii-v1
Full breach record for St. Mary's Health →St. Mary's Health (Indiana) reported to HHS on 2015-03-05 a Hacking/IT Incident affecting 3,952 individuals. On December 3, 2014, a phishing email attack compromised several employees' usernames and passwords. Exposed PHI included patient names, addresses, dates of birth, clinical information, and in some cases, Social Security numbers. Breached information was located in Email systems. OCR obtained documented assurances of corrective action, including deployment of a phishing/malware awareness program.
HIPAA clock✓ HHS notified13 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed3,952 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 5, 2015
- Raw hash
- 0fe734bc4f20134ae5bd94637edf0e3cda4f090b09f3209f2fdd0c00fec2d2cf
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- St. Mary's Healthnorm: st mary s health
- Industry
- Health Care Services
Victim entity
- Name
- St. Mary's Healthnorm: st mary s health
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Dec 3, 2014
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 3,952
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- HHS OCR — corrective action documented
- Initial access
- phishing_link
Compliance
- Time to disclose
- 13 weeks(92 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Dec 3, 2014→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.