Westminster Ingleside King Farm Presbyterian Retirement Communities, Inc.

Sector: healthcare. Reported January 19, 2018. Cause on the record: Hacking or IT incident.

Severity score

25 out of 100 (rubric v1.1)

This score is computed, not assigned. Every component is shown below, and the method is published in full on the severity rubric.

2 of the four components could not be assessed from this record's sources: remediation gap, not reported by this source; notification lag, because a discovery or notification date is not disclosed. The rubric fixes what each scores when the underlying fact is not published, so where a component cannot be assessed this total reflects the limits of the government record as much as the breach itself. It is not directly comparable with a score whose every component was assessable.

Severity score components, their basis, and the points each contributed
ComponentBasisPoints
Data classes exposed1 class(es)22
Scale1,000 to 10,000 records3
Remediation gapnot reported by this source0
Notification lagnot calculable — discovery or notification date not disclosed0
Total25

Data class weights applied

Weight applied to each exposed data class
Data classWeight
Medical records or diagnoses22

What was exposed

Categories of information exposed, and whether each can be changed
Data classPermanence
Medical records or diagnosespermanent

Permanence describes whether the exposed information can be changed. A rotatable value such as a password can be replaced; a permanent one such as a Social Security number cannot.

Records affected

5,228 individuals

Timeline

Timeline of this breach as recorded in its sources
Breach begannot disclosed
Breach endednot disclosed
Discoverednot disclosed
ReportedJanuary 19, 2018

Remediation offered by the entity

The source record does not report remediation offered by the entity. This does not mean none was offered — it means the government record does not state it.

States notified

The source record does not enumerate the states notified.

Litigation

No litigation associated with this breach is recorded here. Litigation and settlement tracking is being added; absence from this page is not evidence that none exists.

Sources

Every fact on this page comes from the government records below.

  1. U.S. Department of Health and Human Services, Office for Civil Rights breach portal (HIPAA) retrieved August 7, 2026