DisclosureLens
Social EngineeringHealthcareHealthcarePhishingStolen CredentialsCustomer Data InvolvedTargetedFinancial accountHealth (basic)Identity (basic)PHILowContained

OVERLAKE MEDICAL CENTER & CLINICS

bd_49723410227a9f16 · schema v1 · pii pii-v1

Severity

Low

Discovered

Jun 14, 2022

Filed

Aug 12, 2022

To disclose

8 weeks

Affected

519state residents only

Linked

2 filings

Confidence

71%
Full breach record for OVERLAKE MEDICAL CENTER & CLINICS2 incidents on file

Overlake Medical Center & Clinics notified Washington AG of unauthorized access to a staff member's email account between June 13-14, 2022. The attacker obtained login credentials. Data accessed included names, DOBs, medical record numbers, and billing info for 519 WA residents. No SSNs or financial account numbers were involved. Notifications sent August 12, 2022.

Washington clock WA AG >30d8 weeks discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 1 days
discovery → filing · 8 weeks / 59 days

Jun 13, 2022

Begins

Jun 14, 2022

Discovered

Aug 12, 2022

Filed

vs. sector median

4 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings

View merged incident ↗
HHS OCRAug 12 · first
Washington State AGAug 12 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.