OHHackingHealthcareHealthcareCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICHighResolved
Greater Cincinnati Behavioral Health
bd_a0db490ef29f1fdb · schema v1 · pii pii-v1
Full breach record for Greater Cincinnati Behavioral Health →Greater Cincinnati Behavioral Health Services (OH) reported to HHS on 2024-02-02 a Hacking/IT Incident affecting 50,000 individuals (60,796 per the web description). Breached information located on a Network Server. PHI involved included names, addresses, dates of birth, Social Security numbers, diagnoses, conditions, lab results, medications, and other treatment information. The CE notified affected individuals, the media, and HHS, and implemented additional administrative, technical, and security safeguards.
Leak gap clock⏱ Leak >30d
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
A leak claim by dragonforce about this victim predates this filing by 51 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_41132c496638b1b9Leak Sitedragonforcefiled 2023-12-13(51d gap)Verified
Regulatory filings (3) · sorted by filing gap
- bd_f65e62cc431b5ba1Indiana State AGfiled 2024-01-25(8d gap)Verified
- bd_94597d00252f3111Maine State AGfiled 2024-06-13(132d gap)Verified by operator
- bd_af604ff30818615eMaine State AGfiled 2024-09-11(222d gap)Verified by operator
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Feb 2, 2024
- Raw hash
- c89e0a71bf3e6c68b2ba8d81eacfe061a8cbd4552cea59b926b67f65f1d46e17
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Greater Cincinnati Behavioral Healthnorm: greater cincinnati behavioral health
- Domain
- gcbhs.com
- Industry
- Health Care Services
Victim entity
- Name
- Greater Cincinnati Behavioral Healthnorm: greater cincinnati behavioral health
- Domain
- gcbhs.com
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Dec 10, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 50,000
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified HHS
Compliance
- Compliance flags
- Leak >30dHHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Dec 10, 2023→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.