INOVA HEALTH SYSTEM FOUNDATION
bd_4cea0b8a1367835a · schema v1 · pii pii-v1
Full breach record for INOVA HEALTH SYSTEM FOUNDATION →6 incidents on fileInova Health System notified patients of a data security incident involving third-party provider Blackbaud. A ransomware attack on Blackbaud between Feb 7 and May 20, 2020, resulted in data exfiltration. Inova was notified on July 16, 2020. Affected data includes names, addresses, DOBs, phone numbers, provider names, dates of service, hospital departments, and philanthropic giving history. SSNs and financial account info were not exposed. Blackbaud paid the ransom to ensure data destruction.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 7, 2020
Begins
Jul 16, 2020
Discovered
Sep 15, 2020
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- HHS OCRbd_cf1753ab447b52542020-09-09 · +6dVerified
- Washington State AGbd_e64407193b9828fb2020-09-09 · +6dVerified
- Oregon State AGbd_c39af1065b9670912020-09-22 · +7dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Sep 9 (VA), last Sep 22 (OR) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.