NESocial EngineeringHealthcareGovernmentHealthcarePhishingBusiness Associate (HIPAA)Customer Data InvolvedPHIPIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIALHEALTH_BASICHighResolved
City of Lincoln Aging Partners
bd_c09dd56d7ad65477 · schema v1 · pii pii-v1
Full breach record for City of Lincoln Aging Partners →City of Lincoln Aging Partners, a HIPAA business associate in Nebraska, reported an email phishing attack that compromised PHI of 1,513 individuals. Exposed data included names, addresses, dates of birth, Social Security numbers, financial information, diagnoses, and other treatment information. The BA notified HHS, affected individuals, the media, and provided substitute notice; it also implemented additional administrative and technical safeguards. OCR provided technical assistance on HIPAA Security Rule obligations.
HIPAA clock✓ HHS notified
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,513 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jul 14, 2021
- Raw hash
- add871007ea820069a88bb655526ca34f62f0fdf96ed327e44d7c7bf079a3725
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- City of Lincoln Aging Partnersnorm: city of lincoln aging
Victim entity
- Name
- City of Lincoln Aging Partnersnorm: city of lincoln aging
- Industry
- Aging services / Government public health
- Industry
- Healthcaresource defaultGovernmentllm
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,513
- Data types
- PHIPIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIALHEALTH_BASIC
- Attack vector
- Phishing
- Threat actor
- ExternalFinancial
- Regulator citations
- HHS OCR
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.