Saint Agnes Medical Center
bd_422360649d53ea71 · schema v1 · pii pii-v1
Saint Agnes Medical Center experienced a Business Email Compromise (BEC) attack on May 2, 2016, where a scammer impersonated the CEO to request W-2 information via email. The incident compromised the 2015 W-2 data (including names, addresses, salaries, withholding info, and Social Security Numbers) of 2,812 employees. No patient data or systems were breached. The organization notified the California Attorney General and offered one year of Experian ProtectMyID Elite credit monitoring to affected employees.
J jump to incidentP pin to compareR raw source
Incident timeline
May 2, 2016
Begins
May 2, 2016
Discovered
May 5, 2016
Filed
vs. sector median
11 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.