HackingStolen CredentialsDelayed DiscoveryCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICMediumActive
COVENANT HEALTH
bd_d2ea8a1171025f54 · schema v1 · pii pii-v1
Full breach record for COVENANT HEALTH →Covenant Health, Inc. notified South Carolina AG of a data breach where an unauthorized party accessed patient IT systems starting May 18, 2025. Incident discovered Dec 10, 2025. Affected data includes names, SSNs, DOBs, medical record numbers, and PHI. Covenant engaged forensic specialists, enhanced IT security, and offered 1-year Experian IdentityWorks.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/2026/Consumer%20Letter%20-%20Covenant%20Health%2C%20Inc..pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 2, 2026
- Raw hash
- ec12df3252dac7963cea9b8ca316f6a8610d01493e560284f557dade89c146a6
Reporting entity
- Name
- COVENANT HEALTHnorm: covenant health
Victim entity
- Name
- COVENANT HEALTHnorm: covenant health
Incident
- Discovered
- Dec 10, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Provided notice to federal law enforcement and appropriate agencies
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 23 days(23 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.