Skip to content

Medico of South Carolina

Disclosed Sep 17, 20197 years ago6,489 affectedConfirmed

Official notice

Medico of South Carolina, Inc., the business associate (BA), reported that an employee inadvertently misconfigured the settings on one of its computer servers, which made the server accessible over the Internet. The server stored the electronic protected health information (ePHI) of 6,489 individuals. The ePHI involved included names, addresses, dates of birth, health insurance information, and treatment information. In its mitigation efforts, the BA implemented additional administrative and technical safeguards to better protect its sensitive data. The BA also sanctioned the responsible employee. The BA notified HHS, affected individuals, the media, and established a call center for questions and concerns. The BA published substitute notice on its website. OCR provided the BA with technical assistance regarding the Breach Notification Rule and obtained assurances that the BA implemented the corrective actions noted.

What is known

People affected6,489 (as reported to HHS)
DisclosedSep 17, 2019
DiscoveredJun 20, 2019
HappenedJun 20, 2019
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
Oregon DOJ breach notice: Medico of South Carolinajustice.oregon.gov · Official notice
HHS OCR breach report (archive, resolved): Medico of South Carolina (Business Associate, SC)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalSep 17, 20196,489
Oregon DOJresidents of ORSep 18, 20196,489
History of this record
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to insider · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 6489 · backfill source
  • 2026-09-25 · disclosed: 2019-09-18 to 2019-09-17 · backfill source
  • 2026-09-25 · summary: empty to Medico of South Carolina, Inc., the business associate (BA), reported that an employee inadvertently misconfigured the settings on one of its computer servers, which made the server accessible over the Internet. The server stored the electr · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Oregon DOJ), confirmed by Oregon DOJ. Record counts are as reported. Not legal advice.

Everything about Medico of South Carolina

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.