HackingStolen CredentialsData ExfiltratedData EncryptedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumActive
Integris Baptist Medical Center, Inc.
bd_4d2ba2292632fe5b · schema v1 · pii pii-v1
Full breach record for Integris Baptist Medical Center, Inc. →Baptist Medical Center (and Resolute Health Hospital) disclosed a cybersecurity incident discovered on April 20, 2022, involving unauthorized access between March 31 and April 24, 2022. An unauthorized third party accessed systems containing personal information, including names, DOBs, SSNs, and medical/billing data, and exfiltrated some data. The organization engaged forensic investigators, contacted law enforcement, suspended access, and offered credit monitoring. The investigation was ongoing at the time of filing.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_7f5ee3e71988e5a2Washington State AGfiled 2022-06-15Verified
- bd_8c181b3d43ffe625Oregon State AGfiled 2022-06-15Verified
- bd_66f57573bbab8612Oregon State AGfiled 2022-06-24(9d gap)Verified
- bd_d9c4212c6a2ed59fCalifornia State AGfiled 2022-06-24(9d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-554297
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 15, 2022
- Raw hash
- 9113949d1c9a43e36764c2e686b827592f9cd745cfa92313b98988dc7d0fd774
Reporting entity
- Name
- Integris Baptist Medical Center, Inc.norm: integris baptist medical center
Victim entity
- Name
- Integris Baptist Medical Center, Inc.norm: integris baptist medical center
Incident
- Discovered
- Apr 20, 2022
- Materiality determined
- Jun 15, 2022
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(56 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.