Region Ten Community Services Board (VA, healthcare provider) reported a credential-phishing incident in which multiple employees responded to an email impersonating an internal sender that warned of mailbox-quota issues and prompted them to enter username and password at a linked site. A forensic investigation did not identify confirmed compromise of sensitive client information, but as a precaution the CE notified 10,228 individuals, issued a press release, and posted notice on its website. The CE engaged a technology consulting firm and provided OCR written assurance of network updates including an additional firewall. OCR breach portal entry filed 2013-09-26; no business associate involved.
Affected (this filing): 10,228