Young Consulting
bd_5ce39f38f478348c · schema v1 · pii pii-v1
Full breach record for Young Consulting →The business associate (BA), Young Consulting LLC, reported that it experienced a ransomware attack that affected the protected health information (PHI) of 961,003 individuals. The PHI involved included names, dates of birth, health insurance information, diagnoses, and other treatment information. The BA notified HHS, affected individuals, the media, law enforcement, and published substitute notice on its website. In response to the breach, the BA reviewed and strengthened its policies and procedures, implemented a variety of additional security software protections, hired additional security staff, and required additional training.
Linked disclosures
Why this link?Ransomware claims (2)
- bd_03c47f5a6450ccf3Leak Siteblacksuitfiled 2024-05-07(127d gap)Verified by operator
- bd_7315ee3ac8363f75Leak Siteblacksuitfiled 2024-04-10(154d gap)Verified by operator
Regulatory filings (5) · sorted by filing gap
- bd_7188534a232b14efWashington State AGfiled 2024-09-18(7d gap)Candidate
- bd_922c90dafda018a6Oregon State AGfiled 2024-08-26(16d gap)Verified by operator
- bd_be91be0598b363e1Montana State AGfiled 2024-08-26(16d gap)Verified by operator
- bd_74ee160876e9cb59California State AGfiled 2025-04-11(212d gap)Verified by operator
Show 1 more filing ↓Show fewer ↑up to 212d gap
- bd_a6f94afdabec5673Maine State AGfiled 2025-04-11(212d gap)Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Sep 11, 2024
- Raw hash
- e127762844a1277f548b7c69edc4518710f1ae67391d16c74ed89b1340b103aa
Source filing
Reporting entity
- Name
- Young Consultingnorm: young consulting
- Domain
- youngconsulting-us.com
- Industry
- Business Associate
Victim entity
- Name
- Young Consultingnorm: young consulting
- Domain
- youngconsulting-us.com
- Industry
- Business Associate
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 961,003
- Data types
- IDENTITY_BASICHEALTH_BASICFINANCIAL_ACCOUNTPHI
- Attack vector
- Unauthorized Access
- Threat actor
- External
- Regulator citations
- Notified HHSNotified law enforcement
Compliance
- Compliance flags
- Leak >90dHHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.