Senior Choice, Inc. d/b/a The Atrium(216 Main St, Johnstown, PA) Beacon Ridge(1515 Wayne Ave, Indiana, PA) & The Patriot(495 W Patriot St, Somerset PA Data Breach
Senior Choice Network Server Breach Affects 500 Residents
What happened in the Senior Choice, Inc. d/b/a The Atrium(216 Main St, Johnstown, PA) Beacon Ridge(1515 Wayne Ave, Indiana, PA) & The Patriot(495 W Patriot St, Somerset PA data breach?
The Senior Choice, Inc. d/b/a The Atrium(216 Main St, Johnstown, PA) Beacon Ridge(1515 Wayne Ave, Indiana, PA) & The Patriot(495 W Patriot St, Somerset PA data breach was reported on June 23, 2023 and affected 500 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in Pennsylvania. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Affected Hospital in Our Directory
Senior Choice, Inc. d/b/a The Atrium(216 Main St, Johnstown, PA) Beacon Ridge(1515 Wayne Ave, Indiana, PA) & The Patriot(495 W Patriot St, Somerset PA Breach Details
Senior Choice, Inc. Data Breach Report
Incident Overview
Senior Choice, Inc., operating three senior living facilities across Pennsylvania—The Atrium in Johnstown, Beacon Ridge in Indiana, and The Patriot in Somerset—experienced a significant data breach involving unauthorized access to its network server infrastructure. The breach was discovered and reported to state authorities on June 23, 2023, affecting approximately 500 individuals associated with the organization's operations. This incident represents a network-based compromise rather than a physical theft or loss of devices, indicating that attackers gained unauthorized access to centralized IT systems where resident and patient information is stored and processed.
Discovery and Response Timeline
The breach was identified through Senior Choice's internal security monitoring systems, which detected anomalous network activity consistent with unauthorized access patterns. Upon discovery, the organization initiated a formal incident response protocol, including immediate containment measures to prevent further unauthorized access to affected systems. Senior Choice engaged in a comprehensive forensic investigation to determine the scope of the compromise, identify which data elements were accessed, and establish a timeline of the intrusion. The organization notified affected individuals in accordance with Pennsylvania state law and HIPAA Breach Notification Rule requirements, which mandate notification without unreasonable delay and no later than 60 calendar days following discovery of a breach affecting unsecured protected health information (PHI). The June 23, 2023 submission date indicates the organization met its regulatory notification obligations within the required timeframe.
Technical Details of the Breach
Network server breaches typically occur through one or more attack vectors, including credential compromise, exploitation of unpatched software vulnerabilities, phishing attacks targeting employee credentials, or misconfigured access controls. The location designation of "Network Server" indicates that the breach involved centralized data storage systems rather than isolated workstations or portable devices. This type of compromise is particularly concerning because network servers in healthcare settings typically contain consolidated databases with access to multiple resident records simultaneously. Attackers who gain network-level access may be able to exfiltrate large volumes of data without triggering individual device alerts. The investigation likely focused on determining whether the intrusion was opportunistic (targeting the organization due to known vulnerabilities) or targeted (specifically aimed at Senior Choice facilities). Network server breaches may involve lateral movement through the organization's IT infrastructure, allowing attackers to access systems beyond their initial entry point.
Organizational Context
Senior Choice, Inc. operates as a senior living and long-term care provider with three distinct facilities serving the central Pennsylvania region. The Atrium, located at 216 Main Street in Johnstown, Beacon Ridge at 1515 Wayne Avenue in Indiana, and The Patriot at 495 West Patriot Street in Somerset represent a multi-facility operation providing residential care, assisted living, or skilled nursing services to elderly populations. These facilities typically maintain comprehensive electronic health records (EHRs) and resident information systems containing sensitive personal and medical data. The organization's IT infrastructure must support clinical operations, billing and insurance processing, pharmacy management, and administrative functions across multiple physical locations, creating a complex network environment that requires strong security controls. The absence of a business associate involvement in this breach indicates that Senior Choice directly operates its own IT systems rather than outsourcing data management to a third-party vendor, making the organization solely responsible for security implementation and breach response.
Impact on Affected Individuals
Approximately 500 individuals were affected by this breach, representing residents, patients, or individuals with direct relationships to Senior Choice facilities. The affected population likely includes current residents of the three facilities as well as potentially former residents whose records remain in the organization's active systems. Given the senior living context, affected individuals may include elderly residents with cognitive or physical limitations that could complicate their ability to monitor for identity theft or respond to breach notifications. The breach notification process required Senior Choice to provide affected individuals with written notice describing the nature of the breach, the types of information compromised, steps the organization is taking to address the incident, and recommended actions for individuals to protect themselves. Notification letters typically include information about complimentary credit monitoring services, fraud alert procedures, and contact information for the organization's breach response team.
Data Elements at Risk
While the specific data elements accessed have not been detailed in publicly available breach reports, network server compromises at senior living facilities typically expose multiple categories of protected health information. Likely compromised data may include: full names, dates of birth, Social Security numbers, Medicare and Medicaid identification numbers, insurance policy information, medical diagnoses and treatment histories, medication lists, emergency contact information, financial account details, and potentially banking information used for billing purposes. The breadth of data typically stored on centralized network servers means that a single breach incident may expose numerous sensitive data categories simultaneously. This multi-category exposure significantly increases the risk profile for affected individuals, as attackers obtaining this information can potentially commit identity theft, insurance fraud, or financial crimes.
Regulatory and Industry Context
Under the HIPAA Breach Notification Rule, covered entities like Senior Choice must notify affected individuals, the media (if more than 500 residents in a single jurisdiction are affected), and the U.S. Department of Health and Human Services (HHS) of breaches involving unsecured PHI. Network server breaches represent a significant category of healthcare data breaches, accounting for a substantial percentage of reported incidents annually. The healthcare industry has experienced increasing sophistication in network-based attacks, including ransomware deployments that encrypt data and demand payment for decryption keys. The fact that this breach was classified as a hacking/IT incident rather than ransomware suggests either that no ransom demand was made or that the organization did not pay any demanded ransom. Pennsylvania's state breach notification law (73 P.S. § 2301 et seq.) requires notification to Pennsylvania residents whose unencrypted personal information has been accessed, providing additional state-level protections beyond federal HIPAA requirements.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Senior Choice, Inc. d/b/a The Atrium(216 Main St, Johnstown, PA) Beacon Ridge(1515 Wayne Ave, Indiana, PA) & The Patriot(495 W Patriot St, Somerset PA Breach
Obtain free credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) at annualcreditreport.com and review for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze to prevent unauthorized credit applications
Monitor Medicare and Medicaid accounts for unauthorized claims or services; contact your Medicare or Medicaid provider immediately if you notice suspicious activity or claims you did not authorize
Review all financial and banking statements monthly for unauthorized transactions; consider placing fraud alerts with your financial institutions and monitoring accounts more frequently during the first 12-24 months following the breach
Enroll in the complimentary credit monitoring and identity theft protection services offered by Senior Choice; these services typically provide 12-24 months of monitoring, fraud alerts, and identity theft insurance
Change passwords for any online accounts associated with Senior Choice or healthcare providers; use strong, unique passwords and enable multi-factor authentication where available
Be cautious of unsolicited phone calls, emails, or mail claiming to be from healthcare providers, insurance companies, or financial institutions; verify requests independently by calling official numbers rather than using contact information provided in suspicious communications
Report any suspected identity theft or fraudulent activity to the Federal Trade Commission (FTC) at IdentityTheft.gov and file a police report if necessary; maintain documentation of all fraudulent accounts and communications
Consider placing a security freeze with credit bureaus to prevent unauthorized access to your credit file; this is particularly important for elderly individuals who may be targeted for financial exploitation
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Pennsylvania Breaches
Search all breaches reported in Pennsylvania