Confluence Health
bd_1e590b3e72a43a2f · schema v1 · pii pii-v1
Full breach record for Confluence Health →2 incidents on fileConfluence Health (WA) reported to HHS on 2018-07-27 a Hacking/IT Incident affecting 33,821 individuals. A Confluence Health employee received and responded to a phishing email on March 29, 2018. An unauthorized external actor accessed the employee's email account from a Nigerian internet address on March 30 and again on May 28, 2018, sent phishing emails to multiple recipients, and auto-deleted sent emails. The account contained PHI including ~32,821 patients' names and treatment information. Breached information located on Email. OCR provided technical assistance on the CE's security management process.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 29, 2018
Begins
Jul 27, 2018
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.