Ascend Clinical, LLC
bd_fc6b4a302719f9a0 · schema v1 · pii pii-v1
Full breach record for Ascend Clinical, LLC →Ascend Clinical, LLC (a California healthcare provider) reported to HHS OCR on 2020-10-19 that an email phishing attack compromising numerous employee mailboxes exposed the ePHI of 77,443 individuals. Exposed data included names, addresses, dates of birth, Social Security numbers, diagnoses, lab results, and prescribed medications. The entity notified HHS, affected individuals, and the media; offered free credit monitoring, identity theft, and fraud protection services; and implemented additional administrative, technical, and security safeguards along with staff retraining.
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_6882f24b5e369f8aMaine State AGfiled 2020-10-23(4d gap)Verified
- bd_43c5891ca65999efCalifornia State AGfiled 2020-10-26(7d gap)Candidate
- bd_80d721f819ea5e74Washington State AGfiled 2020-10-27(8d gap)Verified
- bd_affdc1609c7f455aOregon State AGfiled 2020-10-27(8d gap)Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Oct 19, 2020
- Raw hash
- ab60472e05dec6d2ee407221d10fa5d6af59844ad855f338bf69d423f3330bf5
Source filing
Reporting entity
- Name
- Ascend Clinical, LLCnorm: ascend clinical
- Domain
- labcheck5.com
Victim entity
- Name
- Ascend Clinical, LLCnorm: ascend clinical
- Domain
- labcheck5.com
- Industry
- Healthcare Provider
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 77,443
- Data types
- PHIPIIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Phishing
- Threat actor
- External
- Regulator citations
- HHS OCR breach report
- Initial access
- phishing_link
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.