Thomas Allen
bd_9ac83e45a6417e68 · schema v1 · pii pii-v1
Full breach record for Thomas Allen →Thomas Allen, Inc. reported to HHS on 2022-03-23 a Hacking/IT Incident affecting 2803 individuals. Breached information located on Email. The covered entity reported that several employees were the targets of an email phishing scheme affecting the protected health information (PHI) of 2,803 individuals. The PHI involved included names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers and drivers’ license or state identification numbers, and health insurance and treatment information. The CE notified HHS, the affected individuals, the media, and provided substitute notice. In response to the breach, the CE implemented additional administrative and technical safeguards to better protect its PHI and received technical assistance from OCR regarding the HIPAA Rules.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 23, 2022
- Raw hash
- 2b9153832364f3c20b1399ee859998c304de379339157b014ee2048b0a8e9ac6
Source filing
Reporting entity
- Name
- Thomas Allennorm: thomas allen
- Domain
- thomasalleninc.com
- Industry
- Health Care Services
Victim entity
- Name
- Thomas Allennorm: thomas allen
- Domain
- thomasalleninc.com
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 2,803
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Notified HHSReceived technical assistance from OCR regarding the HIPAA Rules
- Initial access
- phishing_link
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.