USACS Management Group, Ltd.
bd_28f5dd93d1928bcd · schema v1 · pii pii-v1
Full breach record for USACS Management Group, Ltd. →USACS Management Group, Ltd. reported to HHS on 2018-05-08 a Hacking/IT Incident affecting 15,552 individuals. Breached information located on Email. The business associate reported that multiple employees were the victims of an email phishing attack that compromised the protected health information (PHI) of 15,552 individuals. The PHI involved included names, addresses, health insurance information, Social Security numbers, diagnoses/conditions, lab results, medication information, and other treatment information. The BA notified HHS, affected individuals, the media, and provided substitute notice on its website. The BA also offered complimentary identity theft protection services to those affected. In response to the breach, the BA implemented additional administrative, technical, and security safeguards to better protect PHI. Employees were also retrained on email security.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_1b6305722a9ae92aCalifornia State AGfiled 2018-05-08Verified
- bd_ec23e2aaf77d1b4cMontana State AGfiled 2018-05-08Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 8, 2018
- Raw hash
- 86942edaa07264fad948c7e89fedd1c67a8362d348047eb17382ea423f4b2e10
Source filing
Reporting entity
- Name
- USACS Management Group, Ltd.norm: usacs management
- Industry
- Health Care Services
Victim entity
- Name
- USACS Management Group, Ltd.norm: usacs management
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 15,552
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Notified HHS
- Third party
- via USACS Management Group, Ltd.business associate
- Initial access
- phishing_link
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.