DisclosureLens
GLOBALUnknownRansomwareTrigonaLow

Public Health Management Corporation

bd_1c563d0ea5f13725 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

May 8, 2023

To disclose

Affected

Not disclosed

Linked

6 filings

Confidence

60%
Full breach record for Public Health Management Corporation

Press / market disclosure — not a breach-notification filing

A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage — verify against the source.

Phoenician Medical Center Cyberattack Affects Up to 162,500 Patients. Public Health Management Corporation (PHMC): Le Phoenician Medical Center (PMC) recently reported a cyberattack that disrupted some of its computer systems, potentially affecting up to 162,500 current and former patients. The compromised information includes names, contact information, demographic information, dates of birth, state identification numbers, medical record numbers, diagnosis and treatment information, provider names, service dates, prescription information and/or health insurance information. The incident was reported to the HHS Office for Civil Rights. Linked ransomware group: trigona.

Incident timeline — mostly unverified

? — ?

Breach window unknown

May 8, 2023

Press report

Corroborated · see linked filings

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

Attack → press

Compliance clock

Not assessable

This filing is one of 6 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (1)

Regulatory filings (4) · sorted by filing gap

Filing propagation · 5 filings · 4 states

View merged incident ↗
PressMay 8 · first · this page

Pattern: first filing May 8, last Feb 26 (VT) — a 294-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market reportThis record

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • incident type + narrative only (may be machine-translated)
  • discovery date
  • materiality
  • affected count
  • data types
  • compliance clock

The ✕ fields stay blank until a regulatory filing or victim disclosure lands.

About this groupFirst seen 2023-04-11

trigona

According to ransomware.live, According to PCrisk, Trigona is ransomware that encrypts files and appends the ._locked extension to filenames. Also, it drops the how_to_decrypt.hta file that opens a ransom note. An example of how Trigona renames files: it renames 1.jpg to 1.jpg._locked, 2.png to 2.png._locked, and so forth.It embeds the encrypted decryption key, the campaign ID, and the victim ID in the encrypted files.

49 victims claimed globally49 tracked hereFull profile →