Loudoun Medical Group
bd_5e6b9ab4a3822072 · schema v1 · pii pii-v1
Full breach record for Loudoun Medical Group →Loudoun Medical Group d/b/a Comprehensive Sleep Care Center (CSCC), a healthcare provider in Virginia, reported to HHS on 2019-11-27 a Hacking/IT Incident affecting 15,575 individuals. An employee was the victim of an email phishing scheme, exposing PHI including names, addresses, birthdates, diagnoses, clinical information, and treatment information via Email. The CE notified HHS, affected individuals, and the media, provided substitute notice, and implemented additional technical safeguards.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Nov 27, 2019
Filed
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Montana State AGbd_d3f16780c73a51c72019-11-27Verified
- Illinois State AGbd_d9028efc6f2856022019-01-01 · +330dCandidate
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Nov 27 (VA) — a 330-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.