GAHackingHealthcareHealthcarePhishingCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICMediumContained
Tift Regional Medical Center
bd_2a18317cb8be101e · schema v1 · pii pii-v1
Full breach record for Tift Regional Medical Center →Tift Regional Medical Center reported to HHS on 2018-12-18 a Hacking/IT Incident affecting 1045 individuals. Breached information located on Email. An unknown individual gained access to two employee email accounts on June 20, 2018, exposing PHI including names, DOB, and clinical data.
HIPAA clock✓ HHS notified26 weeks discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,045 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Dec 18, 2018
- Raw hash
- 9bdc481fd316390bb629d1a43d6452cf73bfcc6226712a79910861fa4cb0954e
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Tift Regional Medical Centernorm: tift regional medical center
- Industry
- Health Care Services
Victim entity
- Name
- Tift Regional Medical Centernorm: tift regional medical center
- Industry
- Healthcaresource default
Incident
- Discovered
- Jun 20, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,045
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 26 weeks(181 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jun 20, 2018→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.