Clinton Health Access Initiative (CHAI)
bd_54580cabf4cd7477 · schema v1 · pii pii-v1
Full breach record for Clinton Health Access Initiative (CHAI) →CHAI notified employees of a phishing incident on March 21, 2016, where fraudulent emails requesting W-2 forms were sent. Compromised data included names and SSNs. CHAI offered two years of ID theft monitoring and implemented stricter approval processes for personal data requests.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 21, 2016
Begins
Mar 21, 2016
Discovered
Apr 1, 2016
Filed
vs. sector median
10 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.