COMalwareHealthcareHealthcarePHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
LCS
bd_ba4a13b35dcea53b · schema v1 · pii pii-v1
Full breach record for LCS →LCS Financial Services reported to HHS on 2023-10-24 a Hacking/IT Incident affecting 768 individuals. Breached information located on Network Server. The incident involved ransomware encrypting PHI including names, addresses, and SSNs. The BA implemented additional administrative, technical, and security safeguards.
HIPAA clock✓ HHS notified
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.
This filing is one of 10 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- bd_325c9c186e879881Delaware State AGfiled 2023-10-24Verified
- bd_67d6fd7c7ebc7984California State AGfiled 2023-10-24Verified
- bd_9590de5068b55cb1Vermont State AGfiled 2023-10-24Verified
- bd_1dca0a5fdc12edfbVermont State AGfiled 2023-10-05(19d gap)Verified
Show 5 more filings ↓Show fewer ↑up to 32d gap
- bd_3d0bf692d70d11b1Delaware State AGfiled 2023-10-05(19d gap)Candidate
- bd_76f339ccce59c020Delaware State AGfiled 2023-10-05(19d gap)Candidate
- bd_c23ff9723b2552b0California State AGfiled 2023-10-05(19d gap)Candidate
- bd_354d6ed0cdc83cefVermont State AGfiled 2023-09-22(32d gap)Verified
- bd_5db881e7e0b4d1a7California State AGfiled 2023-09-22(32d gap)Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Oct 24, 2023
- Raw hash
- 60c78d97867ea99b3c5a784d502a1b2edbfa5218db880a73ab47bd36139a1f75
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- LCSnorm: lcs
- Domain
- lcsfin.com
- Industry
- Business Associate
Victim entity
- Name
- LCSnorm: lcs
- Domain
- lcsfin.com
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 768
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified HHS
- Third party
- via LCS Financial Servicesbusiness associate
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.