Kentuckiana Regional Planning and Development Agency
bd_3b2d7404d17c9176 · schema v1 · pii pii-v1
Full breach record for Kentuckiana Regional Planning and Development Agency →Kentuckiana Regional Planning and Development Agency (KY) reported to HHS on 2020-06-05 a Hacking/IT Incident affecting 3,663 individuals. Several employees were victims of an email phishing scheme exposing ePHI on Desktop Computer and Email systems. Compromised data included names, dates of birth, Social Security numbers, physical addresses, drivers' license numbers, diagnoses, health insurance information, and claims/financial information. The CE notified HHS, affected individuals, and the media, and implemented additional safeguards and HIPAA retraining for all workforce members.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jun 5, 2020
- Raw hash
- d1eb90bcdac1401e2093538e12cfdc33743fe32d6362e7c6a8226f5cb31e1751
Source filing
Reporting entity
- Name
- Kentuckiana Regional Planning and Development Agencynorm: kentuckiana regional planning and development agency
- Industry
- Health Care Services
Victim entity
- Name
- Kentuckiana Regional Planning and Development Agencynorm: kentuckiana regional planning and development agency
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 3,663
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- HHS OCR notified
- Initial access
- phishing_link
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.