Elmcroft Senior Living, Inc.
ent_41f8cfddda973ace9ca094b9
Disclosures
7
State AG · HHS OCR · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
10,000
nationwide · HHS OCR TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Elmcroft Senior Living, Inc.
- Normalized
- elmcroft senior living— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- South Carolina State AGas victim2018-06-27
Elmcroft Senior Living, Inc. disclosed that an unauthorized third party accessed its Louisville, KY servers on May 10, 2018, exposing personal and health information including SSNs. The incident was discovered on May 12, 2018. Affected individuals were offered one year of identity monitoring through Kroll.
- Delaware State AGas victim2018-06-08
Elmcroft Senior Living, Inc. disclosed a data breach occurring on May 10, 2018, discovered on May 12, 2018. An unauthorized third party accessed servers in Louisville, KY, exposing demographic data, PHI, names, DOBs, addresses, and some SSNs of residents/patients. Elmcroft terminated access, notified law enforcement, and engaged Kroll to provide one year of complimentary identity monitoring and credit monitoring services.
- Massachusetts State AGas victim2018-06-08
Elmcroft Senior Living Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-06-08. 105 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2018-06-08
Elmcroft Senior Living, Inc. notified NH AG of a data breach occurring May 10-12, 2018. An unauthorized third party accessed servers via RDP, exfiltrating patient demographics, SSNs, and PHI. 31 NH residents affected. Notification mailed June 11, 2018. Kroll identity monitoring offered.
- Montana State AGas victim2018-06-08
Elmcroft Senior Living, Inc. reported that on May 10, 2018, an unauthorized third party accessed servers in Louisville, KY, exposing personal and health information (names, DOB, SSN) of former residents. The incident was discovered on May 12, 2018. The company engaged Kroll to provide one year of identity monitoring services to affected individuals.
- California State AGas victim2018-06-01
Elmcroft Senior Living, Inc. reported that an unauthorized third party accessed its servers between May 10 and May 12, 2018. The company became aware of the incident on May 12, 2018, and immediately terminated the unauthorized access. The breach potentially exposed demographic data and personal health information, including names, dates of birth, addresses, and in some instances, social security numbers of residents and patients. The company notified law enforcement and offered one year of identity monitoring services through Kroll.
- TEXASHHS OCRas victim2018-05-21
Elmcroft Senior Living, Inc. (TX) reported to HHS OCR on 2018-05-21 a Hacking/IT Incident affecting 10,000 individuals; breached information was located on a Network Server. Notably, OCR was subsequently notified (2018-09-10) that the entity's skilled nursing and assisted living facilities were transferred to Eclipse Senior Living on 2018-01-21, all healthcare operations have ceased, and Elmcroft Senior Living is no longer a covered entity under HIPAA. No business associate was identified.