Ott Cone & Redpath, P.A.
bd_489f86145f653c99 · schema v1 · pii pii-v1
Full breach record for Ott Cone & Redpath, P.A. →Ott Cone & Redpath, P.A., a North Carolina law firm acting as a HIPAA business associate, reported to HHS OCR on 2024-12-18 that an email phishing attack against employees compromised the PHI of 22,171 individuals. Affected data included names, addresses, dates of birth, Social Security numbers, claims and financial information, diagnoses, conditions, and other treatment information. The firm notified HHS, affected individuals, and the media; posted substitute notice; and remediated by adopting encryption, strengthening policies, and adding technical safeguards.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 31, 2024
Discovered
Dec 18, 2024
Filed
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- New Hampshire State AGbd_15a339fb6f756dd72024-12-16 · +2dVerified
- Montana State AGbd_0be51e9ca9dbbe372024-12-13 · +5dVerified
- Maine State AGbd_4522d49d8820a6c92024-12-13 · +5dVerified
- Maryland State AGbd_cc66493ca7870bbf2025-01-02 · +15dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Dec 13 (MT), last Jan 2 (MD) — a 20-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.