NEW YORKSocial EngineeringHealthcareHealthcarePhishingCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
Oswego County Opportunities
bd_926a6709175ddb3b · schema v1 · pii pii-v1
Full breach record for Oswego County Opportunities →Oswego County Opportunities, Inc. reported to HHS on 2022-05-20 a Hacking/IT Incident affecting 7766 individuals. Breached information located on Email. An employee was the victim of an email phishing attack exposing PHI including names, addresses, DOB, claims, financial info, diagnoses, and lab results. The entity implemented technical safeguards and provided credit monitoring.
HIPAA clock✓ HHS notified
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed7,766 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 20, 2022
- Raw hash
- a9f382f6550b8302261c3775424596e04a224d94312401da07e96e34f98f17b2
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Oswego County Opportunitiesnorm: oswego county opportunities
- Domain
- oco.org
- Industry
- Health Care Services
Victim entity
- Name
- Oswego County Opportunitiesnorm: oswego county opportunities
- Domain
- oco.org
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 7,766
- Data types
- PHIHEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Notified HHS
- Initial access
- phishing_link
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.