South Texas Rehabilitation Hospital
ent_cd4469e2bbfbfd8f09023d24
Disclosures
6
HHS OCR · State AG · 3 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
4,130
nationwide · HHS OCR TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- South Texas Rehabilitation Hospital
- Normalized
- south texas rehabilitation hospital— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (6)newest first
- TEXASHHS OCRas reporting2024-03-29
Weslaco Regional Rehabilitation Hospital reported to HHS on 2024-03-29 a Hacking/IT Incident affecting 2781 individuals. Breached information located on Network Server. The incident involved a ransomware attack encrypting PHI (names, DOB, SSN, driver's license, diagnoses, medications). The entity offered free credit monitoring and implemented additional safeguards.
- TEXASHHS OCRas victim2024-03-29
South Texas Rehabilitation Hospital reported to HHS on 2024-03-29 a Hacking/IT Incident affecting 4130 individuals. Breached information located on Network Server. The incident involved a ransomware attack encrypting PHI (names, DOB, SSN, driver's license, diagnoses, medications). The entity offered credit monitoring and implemented security safeguards.
- Montana State AGas victim2024-03-29
South Texas Rehabilitation Hospital notified Montana residents of a data breach where unauthorized access occurred between Jan 16 and Feb 4, 2024. Patient names and other PII were potentially accessed. The company engaged forensic investigators, isolated systems, and is cooperating with law enforcement. Credit monitoring is offered.
- Illinois State AGas victim2024-03-01
SOUTH TEXAS REHABILITATION HOSPITAL filed a data-breach notice with the Illinois Attorney General in March 2024 (case 24-03-118). The register records the breach as discovered on January 16, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- TEXASHHS OCRas reporting2019-04-08
Weslaco Regional Rehabilitation Hospital reported that it was the victim of an email phishing attack that affected the electronic protected health information (ePHI) of approximately 1,434 individuals. The ePHI involved included names, addresses, birthdates, drivers’ license information, Social Security numbers, diagnoses/conditions, medications prescribed, and other treatment information. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the CE implemented additional administrative, technical, and security safeguards to better protect its sensitive data. Staff members were retrained to properly identify fraudulent email communications. OCR obtained assurances that the CE implemented the corrective actions noted.
- Montana State AGas reporting2019-04-08
Weslaco Regional Rehabilitation Hospital notified patients and staff of unauthorized access to employee email accounts in October 2018, discovered on February 7, 2019. The incident involved phishing leading to credential compromise. Affected data included names, DOBs, health insurance info, and care details. No evidence of misuse was found.