Lutheran Services Carolinas
bd_832000b7234d5329 · schema v1 · pii pii-v1
Full breach record for Lutheran Services Carolinas →The business associate (BA), Lutheran Services Carolinas, reported that it was the victim of a ransomware attack that affected the protected health information (PHI) of 1,226 individuals. The PHI involved included names, addresses, drivers’ license numbers, Social Security numbers, claims and financial information, diagnoses, lab results, and medications. The BA notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the BA implemented additional technical safeguards and provided complimentary credit monitoring services to affected individuals. OCR provided technical assistance regarding the HIPAA Breach Notification Rule.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Apr 12, 2022
- Raw hash
- 0a718d14640b51a5c9b4525b613f7f6d9d7d6feacab13f015ff9bfc40fb627bb
Source filing
Reporting entity
- Name
- Lutheran Services Carolinasnorm: lutheran services carolinas
- Industry
- Business Associate
Victim entity
- Name
- Lutheran Services Carolinasnorm: lutheran services carolinas
- Industry
- Business Associate
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,226
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified HHSOCR provided technical assistance regarding the HIPAA Breach Notification Rule
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.