OREGONMalwareHealthcareHealthcareRansomwareBusiness Associate (HIPAA)Customer Data InvolvedData ExfiltratedData EncryptedRansom DemandedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTCriticalContained
Avamere Health Services, LLC
bd_d6171759266d62f8 · schema v1 · pii pii-v1
Full breach record for Avamere Health Services, LLC →Avamere Health Services, LLC (OR) reported to HHS on 2022-07-13 a Hacking/IT Incident (ransomware attack on its network provider) affecting 229,460 individuals. Breached information was located on a Network Server. PHI involved included names, addresses, dates of birth, driver's license and Social Security numbers, claims and financial information, diagnoses, lab results, and medication data. The BA notified HHS, affected individuals, and the media, offered credit monitoring, and strengthened technical safeguards. OCR provided technical assistance.
HIPAA clock✓ HHS notified
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_a59ac3e65c757f3bLeak Siteavoslockerfiled 2022-12-26(166d gap)Verified by operator
Regulatory filings (5) · sorted by filing gap
- bd_dbfc6c9f626ea5b4New Hampshire State AGfiled 2022-07-16(3d gap)Verified
- bd_8f3805fe6b98937aMaine State AGfiled 2022-07-06(7d gap)Verified by operator
- bd_3bf1b9ebbb2c181eOregon State AGfiled 2022-06-30(13d gap)Verified by operator
- bd_6b1622e1e53f83e8Washington State AGfiled 2022-06-27(16d gap)Verified by operator
Show 1 more filing ↓Show fewer ↑up to 26d gap
- bd_6efd83b0279b1fe4Montana State AGfiled 2022-06-17(26d gap)Verified by operator
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jul 13, 2022
- Raw hash
- 0e7ed5dc9ef29e9c8d13f754d47400e7781a443bbb49e3804301d1a04c146df0
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Avamere Health Services, LLCnorm: avamere health
- Industry
- Business Associate
Victim entity
- Name
- Avamere Health Services, LLCnorm: avamere health
- Industry
- Business Associate
- Industry
- Healthcaresource default
Incident
- Discovered
- May 18, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 229,460
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- OCR provided technical assistance regarding the HIPAA Rules.
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: May 18, 2022→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.