DisclosureLens
Social EngineeringHealthcareHealthcarePhishingTargetedPHIGovernment IDFinancial accountHighContained

Ivy Rehab Network

bd_1b0fad7cc95dd7b0 · schema v1 · pii pii-v1

Severity

High

Discovered

May 1, 2019

Filed

Nov 26, 2019

To disclose

30 weeks

Affected

2,494state residents only

Linked

3 filings

Confidence

65%
Full breach record for Ivy Rehab Network2 incidents on file

Ivy Rehab Network notified individuals in November 2019 that a phishing campaign in May 2019 compromised employee email accounts containing patient PHI, SSNs, and financial data. The company engaged forensic investigators, offered 12 months of Equifax credit monitoring, and implemented password and training reforms. No evidence of misuse was found.

South Carolina clock SC CRA notice due30 weeks discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

discovery → filing · 30 weeks / 209 days

May 1, 2019

Discovered

Nov 26, 2019

Filed

vs. sector median

+18 wks slower

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Montana State AGNov 26 · first
South Carolina State AGNov 26 · first · this page

Pattern: first filing Nov 26 (MT), last Dec 2 (NH) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.