Compassion Care Hospice Las Vegas, LLC
bd_81194d0569b471ca · schema v1 · pii pii-v1
Full breach record for Compassion Care Hospice Las Vegas, LLC →Compassion Care Hospice Las Vegas, LLC reported to HHS on 2017-12-14 a Hacking/IT Incident affecting 1128 individuals. Breached information located on Network Server. On October 28, 2017, an unknown individual gained access to the network and server containing 1,128 patients' protected health information (PHI), specifically demographic and clinical information. Although there was no evidence of access to or exfiltration of PHI, the CE could not rule out that PHI was at risk of compromise. The CE changed credentials, enabled intrusion prevention software, blocked suspicious IPs, disabled remote connection software, blocked its public IP, and took servers offline.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Dec 14, 2017
- Raw hash
- c742309b86bc12429572d8d1dbbe385aa3f5835cbc1efceb4159abd6d7113081
Source filing
Reporting entity
- Name
- Compassion Care Hospice Las Vegas, LLCnorm: compassion care hospice las vegas
- Industry
- Health Care Services
Victim entity
- Name
- Compassion Care Hospice Las Vegas, LLCnorm: compassion care hospice las vegas
- Industry
- Healthcaresource default
Incident
- Discovered
- Oct 28, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,128
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- provided breach notification to HHS
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(47 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Oct 28, 2017→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.