South Texas Rehabilitation Hospital
bd_2cbf4ab481c23b4c · schema v1 · pii pii-v1
Full breach record for South Texas Rehabilitation Hospital →Weslaco Regional Rehabilitation Hospital reported that it was the victim of an email phishing attack that affected the electronic protected health information (ePHI) of approximately 1,434 individuals. The ePHI involved included names, addresses, birthdates, drivers’ license information, Social Security numbers, diagnoses/conditions, medications prescribed, and other treatment information. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the CE implemented additional administrative, technical, and security safeguards to better protect its sensitive data. Staff members were retrained to properly identify fraudulent email communications. OCR obtained assurances that the CE implemented the corrective actions noted.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_b198996611b04115Montana State AGfiled 2019-04-08Candidate
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Apr 8, 2019
- Raw hash
- fb33d9b70a1aba191653ae34f9f80424eab399986dde72c42372c56fa86f6e71
Source filing
Reporting entity
- Name
- South Texas Rehabilitation Hospitalnorm: south texas rehabilitation hospital
- Industry
- Health Care Services
Victim entity
- Name
- South Texas Rehabilitation Hospitalnorm: south texas rehabilitation hospital
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,434
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- Threat actor
- External
- Regulator citations
- The CE notified HHSOCR obtained assurances that the CE implemented the corrective actions noted
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.