DisclosureLens
INDIANASocial EngineeringHealthcareHealthcarePhishingCustomer Data InvolvedHealth (basic)Identity (basic)Government IDHigh

Logansport Memorial Hospital

bd_11899b2550ca4cc0 · schema v1 · pii pii-v1

Severity

High

Discovered

Filed

Apr 23, 2019

To disclose

Affected

7,877

Confidence

50%
Full breach record for Logansport Memorial Hospital

The covered entity (CE), Logansport Memorial Hospital, reported that an employee was the victim of an email phishing scheme that affected the electronic protected health information (ePHI) of approximately 7,877 individuals. The ePHI involved included names, addresses, dates of birth, Social Security numbers, medical record numbers, lab results, and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In addition, the CE provided free credit monitoring services to affected individuals. In its mitigation efforts, the CE sanctioned the responsible employee and implemented additional technical and security measures. All employees were retrained on the proper methods of recognizing and responding to fraudulent email communications. OCR obtained assurances that the CE implemented the corrective actions noted.

HIPAA clock HHS notified
no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.

Incident timeline — partial

? — ?

Breach window unknown

Apr 23, 2019

Filed

No filing yet · watching

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed7,877 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.