MARYLANDMalwareHealthcareHealthcareCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICHighContained
Hope Health Systems Inc.
bd_f64430d2d070d64b · schema v1 · pii pii-v1
Full breach record for Hope Health Systems Inc. →Hope Health Systems Inc. (MD) reported to HHS OCR on 2022-11-21 a Hacking/IT Incident (malware) affecting 9,972 individuals. PHI involved included names, addresses, dates of birth, Social Security numbers, diagnoses, lab results, and medications, located in Electronic Medical Records. The CE notified HHS, affected individuals, and media, posted a substitute notice, offered free credit monitoring, and implemented additional administrative, technical, and security safeguards.
HIPAA clock✓ HHS notified
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_af09eef43ce22cb9Maine State AGfiled 2022-11-21Candidate
- bd_ddf738f179fdbd4fNew Hampshire State AGfiled 2022-11-28(7d gap)Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Nov 21, 2022
- Raw hash
- b75ab33c7274ec63228aabfe9a170dc52e1fd472092cc7e06805ca7b41650e91
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Hope Health Systems Inc.norm: hope health
- Industry
- Health Care Services
Victim entity
- Name
- Hope Health Systems Inc.norm: hope health
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Oct 18, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 9,972
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1204 User ExecutionT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- HHS OCR notified
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Oct 18, 2022→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.