USACS Management Group, Ltd.
bd_28f5dd93d1928bcd · schema v1 · pii pii-v1
Full breach record for USACS Management Group, Ltd. →USACS Management Group, Ltd. reported to HHS on 2018-05-08 a Hacking/IT Incident affecting 15,552 individuals. Breached information located on Email. The business associate reported that multiple employees were the victims of an email phishing attack that compromised the protected health information (PHI) of 15,552 individuals. The PHI involved included names, addresses, health insurance information, Social Security numbers, diagnoses/conditions, lab results, medication information, and other treatment information. The BA notified HHS, affected individuals, the media, and provided substitute notice on its website. The BA also offered complimentary identity theft protection services to those affected. In response to the breach, the BA implemented additional administrative, technical, and security safeguards to better protect PHI. Employees were also retrained on email security.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
May 8, 2018
Filed
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- California State AGbd_1b6305722a9ae92a2018-05-08Verified
- Massachusetts State AGbd_b2e461e9e175b9a12018-05-08Verified
- Montana State AGbd_ec23e2aaf77d1b4c2018-05-08Verified
- New Hampshire State AGbd_54fadeb42e9abe2e2018-05-16 · +8dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing May 8 (CA), last May 16 (NH) — a 8-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.