Public Health Management Corporation
bd_1c563d0ea5f13725 · schema v1 · pii pii-v1
Full breach record for Public Health Management Corporation →Press / market disclosure — not a breach-notification filing
A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage — verify against the source.
Phoenician Medical Center Cyberattack Affects Up to 162,500 Patients. Public Health Management Corporation (PHMC): Le Phoenician Medical Center (PMC) recently reported a cyberattack that disrupted some of its computer systems, potentially affecting up to 162,500 current and former patients. The compromised information includes names, contact information, demographic information, dates of birth, state identification numbers, medical record numbers, diagnosis and treatment information, provider names, service dates, prescription information and/or health insurance information. The incident was reported to the HHS Office for Civil Rights. Linked ransomware group: trigona.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
May 8, 2023
Press report
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Attack → press
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitetrigonabd_458f4399feee2dc12023-06-06 · +29dVerified
Regulatory filings (4) · sorted by filing gap
- HHS OCRbd_dc8c3c91530aa0682023-07-06 · +59dCandidate
- Massachusetts State AGbd_4d5237371c65bb8f2024-02-26 · +294dVerified by operator
- New Hampshire State AGbd_af10819349440b072024-02-26 · +294dVerified by operator
- Vermont State AGbd_b5c251fb8a16298b2024-02-26 · +294dVerified by operator
Filing propagation · 5 filings · 4 states
View merged incident ↗Pattern: first filing May 8, last Feb 26 (VT) — a 294-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- incident type + narrative only (may be machine-translated)
- discovery date
- materiality
- affected count
- data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
trigona
According to ransomware.live, According to PCrisk, Trigona is ransomware that encrypts files and appends the ._locked extension to filenames. Also, it drops the how_to_decrypt.hta file that opens a ransom note. An example of how Trigona renames files: it renames 1.jpg to 1.jpg._locked, 2.png to 2.png._locked, and so forth.It embeds the encrypted decryption key, the campaign ID, and the victim ID in the encrypted files.