Episcopal Health Services
bd_43619738471dcd10 · schema v1 · pii pii-v1
Full breach record for Episcopal Health Services →Episcopal Health Services, Inc. (NY) reported to HHS on 2018-11-19 a Hacking/IT Incident (email phishing scheme) affecting 218,055 individuals. Numerous employees were victims of a phishing attack that compromised ePHI stored in email systems. Exposed data included names, dates of birth, addresses, Social Security numbers, driver's license numbers, financial information, diagnoses, medications prescribed, and other treatment information. The CE notified HHS, affected individuals, and the media, and provided free credit monitoring. New administrative and technical safeguards were implemented; OCR obtained corrective-action assurances.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Nov 19, 2018
- Raw hash
- 3fc7cc02f1737b59a0e2f5b55b216a90e70e876c909c7b741afa03d82167e083
Source filing
Reporting entity
- Name
- Episcopal Health Servicesnorm: episcopal health
- Industry
- Health Care Services
Victim entity
- Name
- Episcopal Health Servicesnorm: episcopal health
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 218,055
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- HHS OCR — corrective action assurances obtained
- Initial access
- phishing_link
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.