DisclosureLens
Social EngineeringHealthcareHealthcarePhishingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryIdentity (basic)Government IDFinancial accountPHIHealth (basic)MediumContained

Health Quest Systems, Inc.

bd_46fbe80968b6b247 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jul 1, 2018

Filed

Jan 10, 2020

To disclose

19 months

Affected

Not disclosed

Linked

3 filings

Confidence

64%
Full breach record for Health Quest Systems, Inc.3 incidents on file

Health Quest Systems, Inc. experienced a phishing incident in July 2018 where employees were tricked into disclosing email credentials. An unauthorized party accessed these accounts. A comprehensive review completed in November 2019 determined that patient information, including names, SSNs, driver's license numbers, passport numbers, financial account info, health insurance info, and clinical data, may have been exposed. The company secured accounts, engaged forensic investigators, and is offering credit monitoring. Remediation includes MFA and security training.

Incident timeline

Jul 11, 2018

Begins

Jan 10, 2020

Filed

vs. sector median

+67 wks slower

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Massachusetts State AGJan 10 · first
Montana State AGJan 10 · first
California State AGJan 10 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.