DisclosureLens
Social EngineeringTechnologyHealthcareInformationPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDFinancial accountMediumContained

HealthInfoNet

bd_022d45b236e30fe2 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jan 25, 2017

Filed

Feb 14, 2017

To disclose

20 days

Affected · nationwide

671 in this filing

Confidence

64%
Full breach record for HealthInfoNet

HealthInfoNet reported a phishing incident on Jan 24, 2017, compromising an employee email account. 67 individuals (including 1 NH resident) were affected. Data accessed may include PII, SSN, and bank details. Notifications sent Feb 9, 2017, offering 1 year credit monitoring.

Incident timeline

undetected · 1 days
discovery → filing · 20 days

Jan 24, 2017

Begins

Jan 25, 2017

Discovered

Feb 14, 2017

Filed

vs. sector median

16 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed67 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.