Lutheran Social Services of South Central Pennsylvania
Disclosed May 20, 201313 years ago7,803 affectedConfirmed
This case involved a hacking incident on the covered entity’s (CE) network server. A Trojan virus was discovered running under an administrative account on a remote access server. No data loss was actually discovered, but potentially 7,300 records may have been vulnerable. The types of protected health information (PHI) potentially breached included demographic, financial, and clinical information. The CE engaged a forensic consulting team to verify the scope and impact of the malware and to clean the system. The CE installed more effective virus detection software, trained and educated users regarding data security, and made adjustments to data storage policies. OCR confirmed that the CE took all appropriate corrective action.
What is known
| People affected | 7,803 (as reported to HHS) |
|---|---|
| Disclosed | May 20, 2013 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Lutheran Social Services of South Central Pennsylvania (Healthcare Provider, PA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | May 20, 2013 | 7,803 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.
Everything about Lutheran Social Services of South Central Pennsylvania