DisclosureLens
MalwareHealthcareProfessional ServicesHealthcareRansomwareSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIdentity (basic)MediumContained

Confluence Health

bd_31cb2a5e12776f0d · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jul 16, 2020

Filed

Aug 14, 2020

To disclose

29 days

Affected

1,132state residents only

Confidence

68%
Full breach record for Confluence Health2 incidents on file

Confluence Health Foundation reported a ransomware incident affecting its third-party vendor, Blackbaud, Inc. Unauthorized access occurred between April 18 and May 7, 2020, resulting in the exfiltration of donor names and dates of birth. The incident was discovered on July 16, 2020, and 1,132 Washington residents were notified on August 14, 2020.

Washington clock WA AG ≤30d29 days discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 89 days
discovery → filing · 29 days

Apr 18, 2020

Begins

Jul 16, 2020

Discovered

Aug 14, 2020

Filed

vs. sector median

8 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,132 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.