AccidentalMisconfigurationData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Bon Secours Health System, Inc.
bd_65734bd13c75f086 · schema v1 · pii pii-v1
Full breach record for Bon Secours Health System, Inc. →Bon Secours Health System, Inc. reported a data breach involving vendor R-C Healthcare Management. Between April 18-21, 2016, a vendor misconfigured network settings, exposing patient files containing names, SSNs, insurance IDs, and limited clinical info. Discovered June 14, 2016, Bon Secours secured the data and offered credit monitoring. No medical records were exposed.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_3c2c6f226fef054aHHS OCRfiled 2016-08-12Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-63348
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 12, 2016
- Raw hash
- 980fc60fc269a191c99810d7be81e98bf782481d6308be6ad9f6cb560faea1a7
Reporting entity
- Name
- Bon Secours Health System, Inc.norm: bon secours health system
Victim entity
- Name
- Bon Secours Health System, Inc.norm: bon secours health system
Incident
- Discovered
- Jun 14, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- Partner
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.