Mercy Hospital, Iowa City, Iowa
bd_312e904dda8c788e · schema v1 · pii pii-v1
Full breach record for Mercy Hospital, Iowa City, Iowa →4 incidents on fileMercy Iowa City notified the New Hampshire Attorney General of a phishing incident where an employee's email account was compromised from May 15, 2020, to June 24, 2020. The unauthorized party accessed personal information including names, SSNs, and medical/insurance data. Eight New Hampshire residents were affected. Mercy secured the account, engaged forensic investigators, and offered 12 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
May 15, 2020
Begins
Jun 24, 2020
Discovered
Dec 1, 2020
Filed
vs. sector median
+10 wks slower
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Maine State AGbd_2a28526c953d48e12020-11-13 · +18dCandidate
- Massachusetts State AGbd_35d6f4ce995941d62020-11-13 · +18dVerified
- HHS OCRbd_cb229a485f2d826b2020-11-13 · +18dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Nov 13 (ME), last Dec 1 (NH) — a 18-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.