DisclosureLens
WASHINGTONSocial EngineeringHealthcareHealthcarePhishingStolen CredentialsCustomer Data InvolvedData ExfiltratedHealth (basic)Identity (basic)MediumResolved

Confluence Health

bd_1e590b3e72a43a2f · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Jul 27, 2018

To disclose

Affected

33,821

Confidence

97%
Full breach record for Confluence Health2 incidents on file

Confluence Health (WA) reported to HHS on 2018-07-27 a Hacking/IT Incident affecting 33,821 individuals. A Confluence Health employee received and responded to a phishing email on March 29, 2018. An unauthorized external actor accessed the employee's email account from a Nigerian internet address on March 30 and again on May 28, 2018, sent phishing emails to multiple recipients, and auto-deleted sent emails. The account contained PHI including ~32,821 patients' names and treatment information. Breached information located on Email. OCR provided technical assistance on the CE's security management process.

HIPAA clock HHS notified
no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.

Incident timeline

Mar 29, 2018

Begins

Jul 27, 2018

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed33,821 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.