CRG Lynwood, LLC
bd_9e946490177e4566 · schema v1 · pii pii-v1
Full breach record for CRG Lynwood, LLC →CRG Lynwood, LLC d/b/a Lynwood Manor (a Michigan healthcare provider) reported to HHS OCR that its business associate experienced a ransomware attack affecting PHI of 6,566 individuals. Affected data included names, dates of birth, driver's license numbers, Social Security numbers, claims and financial information, medications, and other treatment information stored on a network server. The covered entity notified HHS, affected individuals, and the media; provided substitute notice and complimentary credit monitoring; and implemented additional administrative, technical, and security safeguards plus workforce retraining.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_605c836d0f7905f0New Hampshire State AGfiled 2024-06-10Verified
- bd_807a36cceac76c0cMaine State AGfiled 2024-06-10Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jun 10, 2024
- Raw hash
- 8ef9adbd637dd524bbfd0ac52b71a5322b1dd2dbb2b89e4d8306da9cb76fe78a
Source filing
Reporting entity
- Name
- CRG Lynwood, LLCnorm: crg lynwood
- Industry
- Healthcare Provider
Victim entity
- Name
- CRG Lynwood, LLCnorm: crg lynwood
- Industry
- Healthcare Provider
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 6,566
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIALHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- HHS OCR breach report
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.