HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPIIMediumContained
Prisma Health-Midlands
bd_120b6137c4076eee · schema v1 · pii pii-v1
Full breach record for Prisma Health-Midlands →Prisma Health - Midlands notified individuals that a team member's login credentials were compromised on August 29, 2019. The compromised credentials provided access to patient pre-registration and volunteer registration forms on the Palmetto Health website. Affected data included names, dates of birth, SSNs, addresses, and health information. Prisma Health reset the password, blocked access to the forms, and offered one year of free credit monitoring and identity theft insurance.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2019/PrismaHealth.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 1, 2019
- Raw hash
- f04ac1e15d661db5d4b2bafa82f465ca053bd3045dbcb06690761539ee7f32a0
Reporting entity
- Name
- Prisma Healthnorm: prisma health
Victim entity
- Name
- Prisma Health-Midlandsnorm: prisma health midlands
Incident
- Discovered
- Aug 29, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- Internal
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 weeks(64 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.