St. Andrew's Resources for Seniors System
bd_6e405b804d6ffeb3 · schema v1 · pii pii-v1
Full breach record for St. Andrew's Resources for Seniors System →St. Andrew's Resources for Seniors System (a Missouri healthcare provider) reported to HHS OCR that multiple employees were targeted in an email phishing scheme, exposing PHI of 4,434 individuals. Compromised data included names, dates of birth, SSNs, driver's license numbers, addresses, passport information, claims and financial information, diagnoses, lab results, medications, and other treatment information. The entity notified HHS, affected individuals, and the media; retrained workforce on phishing identification; and implemented additional administrative, technical, and security safeguards. No business associate was involved. Breach submitted 2025-02-07; location of breached information: Email.
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_0d1f90635147cec4Montana State AGfiled 2025-02-07Candidate
- bd_6d5d589606fe7c79Maryland State AGfiled 2025-02-07Verified
- bd_70d01264a0919451Indiana State AGfiled 2025-02-07Verified
- bd_732dd450e270af9bOregon State AGfiled 2025-02-07Verified
Show 1 more filing ↓Show fewer ↑
- bd_fbcfd72a1ec6a335Maine State AGfiled 2025-02-07Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Feb 7, 2025
- Raw hash
- ef16e11281ab660bcc5a53f5858c2a4aef6d32d08a526619a3dcf4b2f0982835
Source filing
Reporting entity
- Name
- St. Andrew's Resources for Seniors Systemnorm: st andrew s resources for seniors system
- Domain
- standrews1.com
Victim entity
- Name
- St. Andrew's Resources for Seniors Systemnorm: st andrew s resources for seniors system
- Domain
- standrews1.com
- Industry
- Healthcare Provider
- Industry
- Healthcaresource default
Incident
- Discovered
- Jan 6, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 4,434
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIALHEALTH_BASIC
- Attack vector
- Phishing
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jan 6, 2025→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.