DisclosureLens
Social EngineeringHealthcareHealthcarePhishingTargetedPIIIdentity (basic)Government IDEmploymentMediumContained

Campbell County Health

bd_1e20a62ee9eee234 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jan 25, 2017

Filed

Jan 27, 2017

To disclose

2 days

Affected

6state residents only

Confidence

66%
Full breach record for Campbell County Health

Campbell County Health notified employees that on January 25, 2017, an unauthorized individual impersonated an executive to fraudulently obtain W-2 files containing names, SSNs, and compensation data. The incident involved social engineering (phishing) with no unauthorized network access. The organization contacted law enforcement and offered two years of identity protection services.

Incident timeline

discovery → filing · 2 days

Jan 25, 2017

Begins

Jan 25, 2017

Discovered

Jan 27, 2017

Filed

vs. sector median

12 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed6 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.