Harvard Eye Associates
bd_3bdb3e6c2815d1d0 · schema v1 · pii pii-v1
Full breach record for Harvard Eye Associates →Harvard Eye Associates suffered a ransomware attack via a third-party online data storage vendor. Hackers accessed data as early as Oct 24, 2020, and demanded ransom, which was paid. The vendor notified Harvard Eye on Jan 15, 2021. Affected data included patient PHI (medical history, insurance info) and employee PII (SSN, bank accounts, government IDs). No evidence of data disclosure was found. Identity protection services were offered.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 24, 2020
Begins
Jan 15, 2021
Discovered
Feb 16, 2021
Filed
vs. sector median
8 wks faster
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- HHS OCRbd_36fb89cb0ceb607e2021-02-08 · +8dVerified
Filing propagation · 2 filings
View merged incident ↗Pattern: first filing Feb 8 (CA), last Feb 16 (CA) — a 8-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.