Back to the register

Lutheran Social Services of South Central Pennsylvania

ArchivedSubmitted 05/20/2013
State
PA
Covered entity type
Healthcare Provider
Individuals affected
7,803
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Network Server
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

This case involved a hacking incident on the covered entity’s (CE) network server. A Trojan virus was discovered running under an administrative account on a remote access server. No data loss was actually discovered, but potentially 7,300 records may have been vulnerable. The types of protected health information (PHI) potentially breached included demographic, financial, and clinical information. The CE engaged a forensic consulting team to verify the scope and impact of the malware and to clean the system. The CE installed more effective virus detection software, trained and educated users regarding data security, and made adjustments to data storage policies. OCR confirmed that the CE took all appropriate corrective action.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.