TNHackingHealthcareHealthcarePhishingData ExfiltratedCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICMediumResolved
Monroe Operations, LLC
bd_58064c72c6e74804 · schema v1 · pii pii-v1
Full breach record for Monroe Operations, LLC →Monroe Operations, LLC d/b/a Newport Academy and Center for Families reported to HHS on 2018-08-17 a Hacking/IT Incident affecting 1165 individuals. Breached information located on Email. An employee's account was phished on 2018-02-22, leading to unauthorized access and exfiltration of PHI including demographic and health insurance data.
HIPAA clock✓ HHS notified8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,165 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Aug 17, 2018
- Raw hash
- 7bbeec4137d33ec39d2404c59467e637fac8cba076a5aba8a33920fa47fe524b
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Monroe Operations, LLCnorm: monroe operations
- Industry
- Health Care Services
Victim entity
- Name
- Monroe Operations, LLCnorm: monroe operations
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Jun 20, 2018
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,165
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1114 Email Collection
- Threat actor
- External
- Regulator citations
- provided breach notification to HHSOCR provided technical assistance on automating review of the CE's computer system and the importance of regular HIPAA trainingOCR obtained assurance that the CE implemented the corrective actions listed above
- Initial access
- phishing_link
Compliance
- Time to disclose
- 8 weeks(58 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jun 20, 2018→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.