OVERLAKE MEDICAL CENTER & CLINICS
bd_21978de6822b001b · schema v1 · pii pii-v1
Full breach record for OVERLAKE MEDICAL CENTER & CLINICS →2 incidents on fileOverlake Medical Center & Clinics notified Montana AG of a phishing incident where attackers stole credentials for one email account on Dec 6, 2019. Attackers accessed the account through Dec 9, 2019, potentially exposing patient PII and PHI. Overlake secured accounts, reset passwords, and implemented MFA.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 6, 2019
Begins
Dec 9, 2019
Discovered
Feb 7, 2020
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- HHS OCRbd_10ffcc7ae52ef6772020-02-07Verified
- California State AGbd_275afc788816b9c62020-02-07Verified
- Oregon State AGbd_69c1780df1b141992020-02-07Verified
- Illinois State AGbd_7b73dfeed69ec4372020-01-01 · +37dCandidate
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Feb 7 (MT) — a 37-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.