Weslaco Regional Rehabilitation Hospital
bd_2cbf4ab481c23b4c · schema v1 · pii pii-v1
Weslaco Regional Rehabilitation Hospital reported that it was the victim of an email phishing attack that affected the electronic protected health information (ePHI) of approximately 1,434 individuals. The ePHI involved included names, addresses, birthdates, drivers’ license information, Social Security numbers, diagnoses/conditions, medications prescribed, and other treatment information. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the CE implemented additional administrative, technical, and security safeguards to better protect its sensitive data. Staff members were retrained to properly identify fraudulent email communications. OCR obtained assurances that the CE implemented the corrective actions noted.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Apr 8, 2019
Filed
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- Montana State AGbd_b198996611b041152019-04-08Candidate
Filing propagation · 2 filings · 2 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.