DisclosureLens
HackingHealthcareHealthcareSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIPHIIdentity (basic)Government IDHealth (basic)MediumContained

Entira Family Clinics

bd_3044d05610370199 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Jan 13, 2022

To disclose

Affected

Not disclosed

Linked

2 filings

Confidence

83%

Entira Family Clinics, a Minnesota-based family medicine practice, notified patients of a data security incident involving its third-party hosting and cloud IT provider, Netgain. An unauthorized party accessed Netgain's environment, potentially exposing patient name, address, Social Security number, and medical history. The breach date recorded is December 4, 2020; notice letters were sent in January 2022. Affected individuals were offered free IDX credit monitoring.

Incident timeline

Dec 4, 2020

Begins

Jan 13, 2022

Filed

This filing is one of 2 about the same incident.View merged incident
Part of Netgain Networks supply-chain incident (2021) — a supply-chain cascade affecting multiple organizations.View cascade →

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Maine State AGJan 13 · first
California State AGJan 13 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.