Jefferson Healthcare
bd_c9796f25cf31fc43 · schema v1 · pii pii-v1
Full breach record for Jefferson Healthcare →Jefferson Healthcare (WA) reported to HHS on 2021-01-11 a Hacking/IT Incident affecting 2,543 individuals. An employee was the victim of an email phishing attack that compromised ePHI including names, addresses, dates of birth, driver's license numbers, Social Security numbers, financial information, claims information, diagnoses, lab results, and medications. Breached information was located in Email. The CE notified HHS, affected individuals, the media, and provided substitute notice on its website, and implemented additional technical safeguards and staff retraining.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_678cccb46681fc86Washington State AGfiled 2021-01-11Candidate
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jan 11, 2021
- Raw hash
- b8c03dbcd4344b9cd6a0fb223950c6ec04eb5b9914208ec12b243c530aa3f103
Source filing
Reporting entity
- Name
- Jefferson Healthcarenorm: jefferson healthcare
- Industry
- Health Care Services
Victim entity
- Name
- Jefferson Healthcarenorm: jefferson healthcare
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 2,543
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- HHS OCR notified
- Initial access
- phishing_link
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.