MisusePrivilege AbuseEmployee Data InvolvedPHIHEALTH_BASICIDENTITY_BASICLowContained
Elizabeth Hospice
bd_95e37044e8aba554 · schema v1 · pii pii-v1
Full breach record for Elizabeth Hospice →The Elizabeth Hospice notified Delaware AG on Dec 14, 2022, regarding an incident where a former employee forwarded business emails to a personal account between Oct 21 and Nov 14, 2022. Exposed data included names, admission/discharge dates, patient account numbers, and basic health info (PHI). No SSN or financial data was involved. The organization investigated and found no evidence of misuse.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_0d11391261f5bdd3California State AGfiled 2022-12-14Candidate
- bd_77ca191b5ef8a2f6Montana State AGfiled 2022-12-14Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2022/12/TEH-Ex.-A.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 14, 2022
- Raw hash
- 1870e93e79ad21fe637441bc4d193e42e62b064303d37e6e1e62d65c3ba9e5c7
Reporting entity
- Name
- Elizabeth Hospicenorm: elizabeth hospice
- Domain
- elizabethhospice.org
Victim entity
- Name
- Elizabeth Hospicenorm: elizabeth hospice
- Domain
- elizabethhospice.org
Incident
- Discovered
- Oct 21, 2022
- Materiality determined
- —
- Notification sent
- Dec 14, 2022
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- Internal
- Initial access
- insider_action
Compliance
- Time to disclose
- 8 weeks(54 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.