DisclosureLens
HackingHealthcareProfessional ServicesHealthcareStolen CredentialsData MishandlingSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIdentity (basic)Government IDFinancial accountMediumContained

Doylestown Hospital and Doylestown Health Physicians

bd_3904025c965fd7e5 · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 20, 2020

Filed

Aug 5, 2020

To disclose

11 weeks

Affected

1state residents only

Linked

2 filings

Confidence

66%
Full breach record for Doylestown Hospital and Doylestown Health Physicians

Doylestown Hospital and Doylestown Health Physicians notified the NH AG of a third-party breach involving PaperlessPay. Access to PaperlessPay's SQL server occurred on Feb 18, 2020, via stolen credentials. The incident exposed employee PII including SSNs and bank details. One NH resident was identified as potentially impacted. Notification sent Aug 4, 2020.

Incident timeline

undetected · 92 days
discovery → filing · 11 weeks / 77 days

Feb 18, 2020

Begins

May 20, 2020

Discovered

Aug 5, 2020

Filed

vs. sector median

on median

This filing is one of 2 about the same incident.View merged incident
Part of PaperlessPay Corporation supply-chain incident (2020) — a supply-chain cascade affecting multiple organizations.View cascade →

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
New Hampshire State AGAug 5 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.