DisclosureLens
HackingHealthcareHealthcareData ExfiltratedData EncryptedCustomer Data InvolvedIdentity (basic)Government IDHealth (basic)Financial accountHighContained

South Carolina Public Employee Benefit (PEBA)

bd_cb4bad466e36ba94 · schema v1 · pii pii-v1

Severity

High

Discovered

Nov 9, 2021

Filed

Jan 24, 2022

To disclose

11 weeks

Affected

1,006state residents only

Confidence

67%
Full breach record for South Carolina Public Employee Benefit (PEBA)

Medical Review Institute of America (MRIoA) notified South Carolina Public Employee Benefit (PEBA) of a cyber-attack discovered on November 9, 2021. The incident involved unauthorized access to systems containing protected health information (PHI), including names, SSNs, and medical history. MRIoA engaged forensic experts, contacted the FBI, and confirmed deletion of exfiltrated data. Affected individuals received one year of identity monitoring via Kroll. No evidence of misuse was found at the time of notification.

South Carolina clock SC CRA notice due11 weeks discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

discovery → filing · 11 weeks / 76 days

Nov 9, 2021

Discovered

Jan 24, 2022

Filed

vs. sector median

2 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,006 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.