Highlands-Cashiers Hospital
bd_19882848e7b76d9b · schema v1 · pii pii-v1
Full breach record for Highlands-Cashiers Hospital →Highlands Cashier Hospital reported to HHS on 2014-12-11 a breach involving unauthorized access or disclosure that affected 26,115 individuals. A business associate, Computer Programs and Systems, Inc., incorrectly configured the hospital's firewall, which exposed patient data on the internet. The exposed information, located on a network server, included patient names, addresses, dates of birth, treatment details, and, for 21,072 individuals, Social Security numbers. In response, the hospital implemented enhanced firewall safeguards, started monitoring web traffic, and began conducting external vulnerability scans.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Dec 11, 2014
Filed
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Massachusetts State AGbd_6907a0be7cb632db2014-11-28 · +13dVerified
- New Hampshire State AGbd_fedf26b9ee7eb5ff2014-11-26 · +15dCandidate
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Nov 26 (NH), last Dec 11 (NC) — a 15-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.