River City Insurance Group
bd_062f4dc5ac9a9f71 · schema v1 · pii pii-v1
Full breach record for River City Insurance Group →River City Insurance Group d/b/a Lavinder Group & Associates reported to HHS on 2022-04-05 a Hacking/IT Incident affecting 1,118 individuals. Breached information located on Email. The business associate reported that multiple employees were the victims of an email phishing scheme that compromised the protected health information (PHI) of 1,118 individuals. The PHI involved included names, drivers’ license numbers, Social Security numbers, diagnoses, and claims and financial information. In response to the breach, the BA provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards. Staff were retrained on email security.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Apr 5, 2022
- Raw hash
- 964a6aca9af700809b1c1a8dfe23de1c7e8e537a653d2ca9695bd715d433eaaf
Source filing
Reporting entity
- Name
- River City Insurance Groupnorm: river city insurance
- Domain
- rivercityinsurancegroup.com
- Industry
- Health Care Services
Victim entity
- Name
- River City Insurance Groupnorm: river city insurance
- Domain
- rivercityinsurancegroup.com
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- Apr 5, 2022
- Affected individuals
- 1,118
- Data types
- PHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Third party
- via River City Insurance Group d/b/a Lavinder Group & Associatesbusiness associate
- Initial access
- phishing_link
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: Apr 5, 2022— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.