University of Washington
bd_4ecc99dad6670eb7 · schema v1 · pii pii-v1
Full breach record for University of Washington →7 incidents on fileUniversity of Washington Medical Center disclosed a security incident where a database configuration error exposed internal files containing PHI (names, medical record numbers, treatment descriptions) to the internet. The breach affected approximately 974,351 individuals, with 894,272 in Washington. Discovery occurred on Dec 26, 2018, after the exposure began on Dec 4, 2018. No SSNs or financial data were involved. Remediation included suspending server changes, engaging consultants, and disabling directory browsing.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 4, 2018
Begins
Dec 26, 2018
Discovered
Feb 20, 2019
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Montana State AGbd_3adad2f84e312d482019-02-20Verified by operator
- HHS OCRbd_721496fd43b47b112019-02-20Verified by operator
- California State AGbd_d6512ec60a11cad62019-02-20Verified by operator
- Oregon State AGbd_0968762279005b792019-02-25 · +5dCandidate
Filing propagation · 5 filings · 4 states
View merged incident ↗Pattern: first filing Feb 20 (MT), last Feb 25 (OR) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.