DisclosureLens
MalwareHealthcareHealthcareRansomwareRansom DemandedTargetedPIIPHIIdentity (basic)Government IDFinancial accountMediumContained

Gretna Family Health

bd_212ed90c0f8fd2bb · schema v1 · pii pii-v1

Severity

Medium

Discovered

Feb 6, 2023

Filed

May 24, 2023

To disclose

15 weeks

Affected

1state residents only

Confidence

66%
Full breach record for Gretna Family Health2 incidents on file

Gretna Family Health, a primary care clinic in Nebraska, notified patients of a cybersecurity attack detected on February 6, 2023. An unauthorized third party attempted to infiltrate the network and demand ransom. Potential exposure of PII, PHI, SSNs, and health insurance info. No evidence of misuse found. Credit monitoring offered.

Incident timeline

discovery → filing · 15 weeks / 107 days

Feb 6, 2023

Begins

Feb 6, 2023

Discovered

May 24, 2023

Filed

vs. sector median

+3 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.