Louisiana Health Cooperative, Inc. in Rehabilitation
bd_b47dcb282e9640b2 · schema v1 · pii pii-v1
Full breach record for Louisiana Health Cooperative, Inc. in Rehabilitation →OCR opened an investigation of Louisiana Health Cooperative, Inc. (CE) after it reported a breach involving its business associate, Summit Reinsurance Services, Inc. (BA). The BA discovered ransomware on a server containing unencrypted ePHI of approximately 8,000 CE members. Affected ePHI included Social Security numbers, insurance and treatment information, and other demographic information. The BA investigated, the CE notified HHS and posted substitute notice on its website, and the BA notified affected individuals and the media. OCR verified a proper BA agreement was in place.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Nov 30, 2016
- Raw hash
- fb9dc6bcbaba7daed4b9dbe67ddb0ea4b04b090aa450156dd4c2e6784c618c0f
Source filing
Reporting entity
- Name
- Louisiana Health Cooperative, Inc. in Rehabilitationnorm: louisiana health cooperative inc in rehabilitation
Victim entity
- Name
- Louisiana Health Cooperative, Inc. in Rehabilitationnorm: louisiana health cooperative inc in rehabilitation
- Industry
- Health Plan
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 8,000
- Data types
- PHIIDENTITY_GOVERNMENTHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Ransomware
- Threat actor
- ExternalFinancial
- Regulator citations
- OCR investigation openedOCR verified proper BA agreement in place
- Third party
- via Summit Reinsurance Services, Inc.
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.