Heart South Cardiovascular Group
bd_7927d296f02ce5db · schema v1 · pii pii-v1
Full breach record for Heart South Cardiovascular Group →Heart South Cardiovascular Group (AL), a cardiovascular healthcare provider, reported to HHS OCR on 2024-06-13 a ransomware attack affecting 20,577 individuals. Compromised PHI on a network server included names, addresses, dates of birth, driver's license numbers, SSNs, diagnoses, lab results, medications, health insurance information, claims/financial data, and other treatment information. The CE notified HHS, individuals, and the media, implemented new technical safeguards, and retrained workforce members. OCR provided technical assistance on the HIPAA Breach Notification Rule.
Linked disclosures
Why this link?Ransomware claims (1)
- bd_2028c3f599016886Leak Siterhysidafiled 2025-11-10(516d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_dc4e83aef803c891Maine State AGfiled 2026-04-06(662d gap)Verified
- bd_718fd6945d5f1904New Hampshire State AGfiled 2026-04-13(669d gap)Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jun 13, 2024
- Raw hash
- 5e943f5c05240753aea6c450211c4ecacec0e65409cdf2dde36e21332a7ba6b4
Source filing
Reporting entity
- Name
- Heart South Cardiovascular Groupnorm: heart south cardiovascular
- Domain
- heartsouthpc.com
- Industry
- Health Care Services
Victim entity
- Name
- Heart South Cardiovascular Groupnorm: heart south cardiovascular
- Domain
- heartsouthpc.com
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 20,577
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- HHS OCR notifiedOCR provided technical assistance regarding the HIPAA Breach Notification Rule
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.