SOUTH CAROLINASocial EngineeringHealthcareHealthcarePhishingStolen CredentialsCustomer Data InvolvedMulti-Stage ChainPHIHEALTH_BASICIDENTITY_BASICCREDENTIALSMediumContained
Roper St. Francis Healthcare
bd_c747a368a1a657f3 · schema v1 · pii pii-v1
Full breach record for Roper St. Francis Healthcare →Roper St. Francis Healthcare reported to HHS on 2019-01-29 a Hacking/IT Incident affecting 35253 individuals. Breached information located on Email. Employees followed phishing links and provided credentials, allowing unauthorized access to PHI.
HIPAA clockDiscovered Nov 19, 2018 → Notified Jan 29, 201971d ✗ HIPAA 60-day late10 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed35,253 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jan 29, 2019
- Raw hash
- acbc69bfabc826b1c46d282eafd0ffd8df13a13920601b2f54e606b4bd038636
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Roper St. Francis Healthcarenorm: roper st francis healthcare
- Domain
- rsfh.com
- Industry
- Health Care Services
Victim entity
- Name
- Roper St. Francis Healthcarenorm: roper st francis healthcare
- Domain
- rsfh.com
- Industry
- Healthcaresource default
Incident
- Discovered
- Nov 19, 2018
- Materiality determined
- —
- Notification sent
- Jan 29, 2019
- Affected individuals
- 35,253
- Data types
- PHIHEALTH_BASICIDENTITY_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 10 weeks(71 days from discovery to filing)
- Compliance flags
- HIPAA 60-day late · 71dHHS notified · 71d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Nov 19, 2018→ Notified: Jan 29, 201971d 60 days HIPAA 60-day late HIPAA Discovered: Nov 19, 2018→ Notified: Jan 29, 201971d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.