FEDERALHackingHealthcareHealthcareBusiness Associate (HIPAA)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICCritical
NASCO Industries Inc
bd_d79917b33aef60e8 · schema v1 · pii pii-v1
Full breach record for NASCO Industries Inc →NASCO, a business associate, reported to HHS on October 10, 2023, a hacking incident that affected 1,744,655 individuals. The breach occurred on a network server and was caused by an exposed software application. The compromised protected health information (PHI) included names, dates of birth, addresses, Social Security numbers, diagnoses, and claims information. In response, NASCO provided complimentary credit monitoring and implemented enhanced security safeguards.
Leak gap clock✗ Leak >180d
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by dispossessor about this victim predates this filing by 294 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_c465e200e2f131f9Leak Sitedispossessorfiled 2022-12-20(294d gap)Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Oct 10, 2023
- Raw hash
- 73937682342b57c45ad11cd0be70c433c8683a0232571674fccc461a30d1e660
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- NASCO Industries Incnorm: nasco industries
- Domain
- nasco.com
- Industry
- Business Associate
Victim entity
- Name
- NASCO Industries Incnorm: nasco industries
- Domain
- nasco.com
- Industry
- Business Associate
- Industry
- Healthcaresource default
Incident
- Discovered
- Aug 21, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,744,655
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- Regulator citations
- Notified HHS
Compliance
- Compliance flags
- Leak >180dHHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Aug 21, 2023→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.