DisclosureLens
Social EngineeringHealthcareHealthcarePhishingBECEmployee Data InvolvedTargetedGovernment IDIdentity (basic)EmploymentHighContained

Saint Agnes Medical Center

bd_422360649d53ea71 · schema v1 · pii pii-v1

Severity

High

Discovered

May 2, 2016

Filed

May 5, 2016

To disclose

3 days

Affected

2,812

Confidence

65%

Saint Agnes Medical Center experienced a Business Email Compromise (BEC) attack on May 2, 2016, where a scammer impersonated the CEO to request W-2 information via email. The incident compromised the 2015 W-2 data (including names, addresses, salaries, withholding info, and Social Security Numbers) of 2,812 employees. No patient data or systems were breached. The organization notified the California Attorney General and offered one year of Experian ProtectMyID Elite credit monitoring to affected employees.

California clockDiscovered May 2, 2016Notified May 4, 20162d CA 60-day OK3 days discovery → filing

Incident timeline

discovery → filing · 3 days

May 2, 2016

Begins

May 2, 2016

Discovered

May 5, 2016

Filed

vs. sector median

11 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2,812 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.