DisclosureLens
HackingHealthcareHealthcareStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIdentity (basic)Government IDFinancialMediumContained

GRAHAM HOSPITAL ASSOCIATION

bd_1783a5fb7a5fe911 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Aug 11, 2020

Filed

Oct 7, 2020

To disclose

8 weeks

Affected

1state residents only

Confidence

66%
Full breach record for GRAHAM HOSPITAL ASSOCIATION

Graham Hospital Association notified employees of a third-party vendor breach involving PaperlessPay. Unauthorized access to PaperlessPay's SQL server occurred on Feb 18, 2020, exposing employee names, addresses, SSNs, and financial data. Graham Hospital determined on Aug 11, 2020, that impacted servers held this data. No fraud confirmed. Affected employees offered 1-year Experian IdentityWorks.

Incident timeline

undetected · 175 days
discovery → filing · 8 weeks / 57 days

Feb 18, 2020

Begins

Aug 11, 2020

Discovered

Oct 7, 2020

Filed

vs. sector median

4 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.