Commission on Economic Opportunity
bd_d1e2aba846f02236 · schema v1 · pii pii-v1
Full breach record for Commission on Economic Opportunity →Commission on Economic Opportunity reported to HHS on 2021-11-30 a Hacking/IT Incident affecting 29454 individuals. Breached information located on Network Server. The business associate was the victim of a ransomware attack affecting the protected health information (PHI) of 29,454 individuals. The PHI involved included names, addresses, dates of birth, and diagnoses. The BA notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the BA implemented additional administrative, technical, and physical safeguards. The BA also provided training to its staff regarding its newly revised policies and procedures designed to protect PHI.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Nov 30, 2021
- Raw hash
- 266a32389dbd25e7efe6a2699827fa395a399cec3a1b5c82b2a01ce7f2ee16da
Source filing
Reporting entity
- Name
- Commission on Economic Opportunitynorm: commission on economic opportunity
- Domain
- ceopeoplehelpingpeople.org
- Industry
- Business Associate
Victim entity
- Name
- Commission on Economic Opportunitynorm: commission on economic opportunity
- Domain
- ceopeoplehelpingpeople.org
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 29,454
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified HHS
- Third party
- via Commission on Economic Opportunitybusiness associate
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.