Cancer Treatment Centers of America
bd_1ca373962cb4dd11 · schema v1 · pii pii-v1
Full breach record for Cancer Treatment Centers of America →7 incidents on fileCTCA Southeastern Regional Medical Center notified Montana residents of a phishing attack on March 11, 2019, which compromised an employee's email account. Affected data included names, medical record numbers, health insurance info, and government IDs. No SSN or financial data was involved. CTCA engaged forensic investigators and reset credentials.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 10, 2019
Begins
Mar 11, 2019
Discovered
May 10, 2019
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- HHS OCRbd_d8567801696f79062019-05-10Verified
- New Hampshire State AGbd_d32cb69426d4bec82019-05-12 · +2dVerified
- Massachusetts State AGbd_4b2273328be2fcbe2019-05-13 · +3dVerified
- Oregon State AGbd_2439022dedecb8ad2019-05-21 · +11dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing May 10 (GA), last May 21 (OR) — a 11-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.