American College of Emergency Physicians
bd_0be2e5afe6e91c9b · schema v1 · pii pii-v1
Full breach record for American College of Emergency Physicians →4 incidents on fileAmerican College of Emergency Physicians (ACEP) notified Washington AG of a cyberattack affecting 4,148 residents. Unauthorized access to a server storing SQL database credentials occurred between April 8 and September 21, 2020. ACEP discovered the incident on September 7, 2020. Data at risk included names, SSNs, financial accounts, and hashed passwords. ACEP rebuilt the server, changed passwords, and offered 12 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 8, 2020
Begins
Sep 7, 2020
Discovered
Apr 9, 2021
Filed
vs. sector median
+20 wks slower
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Montana State AGbd_1bb2a01b4668a1372021-04-09Verified by operator
- California State AGbd_5f96d4f3a86108802021-04-09Verified
- Maine State AGbd_efb6dea5be6ec97b2021-04-09Verified
- Oregon State AGbd_ffe93d10949599602021-04-09Verified
Show 1 more filing ↓Show fewer ↑up to 7d gap
- New Hampshire State AGbd_e272ba1b8b5522522021-04-16 · +7dVerified
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Apr 9 (MT), last Apr 16 (NH) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.