Self Regional Healthcare
ent_4e8fa5754b1317493257ffa9
Disclosures
7
HHS OCR · State AG · 4 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
52,327
nationwide · HHS OCR SC
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Self Regional Healthcare
- Normalized
- self regional healthcare— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- SOUTH CAROLINAHHS OCRas victim2025-07-17
Self Regional Healthcare (Greenwood, SC) reported to HHS OCR on 2025-07-17 a Hacking/IT Incident affecting 26,696 individuals. Breached information was located on a Network Server. A business associate was present. No further detail was provided in the HHS web description.
- South Carolina State AGas victim2025-07-17
Self Regional Healthcare (SRH) notified affected individuals that Nationwide Recovery Services (NRS), a former debt collection vendor, experienced unauthorized access to its network in July 2024. Files containing patient data from 2012-2013 were copied. Data exposed includes names, DOBs, SSNs, diagnoses, and medical info. NRS discovered the breach on July 11, 2024. SRH is offering 12 months of IDX identity protection.
- Vermont State AGas victim2024-07-24
Self Regional Healthcare notified consumers of a data breach involving third-party vendor Medibase Group, Inc. Unauthorized access occurred around Jan 26, 2024, discovered May 28, 2024. Affected data included names, SSNs, DOBs, and financial balances. No clinical data was impacted. Medibase engaged forensic investigators and reported to federal law enforcement. Affected individuals offered credit monitoring.
- SOUTH CAROLINAHHS OCRas victim2019-10-21
Self Regional Healthcare (SC) reported to HHS on 2019-10-21 a Hacking/IT Incident (email phishing scheme) affecting 52,327 individuals. Breached ePHI located in Email systems included names, dates of birth, addresses, health insurance information, Social Security numbers, and other treatment information. The CE notified HHS, affected individuals, and the media, and retrained staff on recognizing fraudulent email communications.
- Illinois State AGas victim2019-01-01
SELF REGIONAL HEALTHCARE filed a data-breach notice with the Illinois Attorney General during 2019 (case 2019-424). The register records the breach as discovered on July 18, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGas victim2014-07-28
Self Regional Healthcare reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2014-07-28. 5 Massachusetts residents were affected. The report records the breach type as electronic.
- SOUTH CAROLINAHHS OCRas victim2014-07-25
On May 25, 2014, a password-protected but unencrypted laptop containing the PHI of 38,906 patients was stolen from Self Regional Healthcare's administrative offices in SC during a break-in. Breached data included names, SSNs, driver's license numbers, treating physician names, insurance policy numbers, account numbers, service dates, diagnosis/procedure information, payment card data, financial account information, and possibly addresses. The CE notified HHS, media, and individuals; offered credit monitoring; engaged police; revised HIPAA policies; retrained staff; improved physical access controls; and encrypted computers. OCR obtained assurances of corrective action.
Supply-chain cascadesreviewed and confirmed
- Self Regional Healthcare’s filing is one of at least 12 in the Nationwide Recovery Services, Inc. supply-chain incident (2025).