DisclosureLens
Social EngineeringHealthcareHealthcarePhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedMulti-Stage ChainPHIGovernment IDIdentity (basic)Financial accountBiometricHighContained

Ransom Memorial Hospital

bd_575fe3ff602c8e05 · schema v1 · pii pii-v1

Severity

High

Discovered

Sep 24, 2018

Filed

Oct 19, 2018

To disclose

25 days

Affected · nationwide

16,3661 in this filing

Confidence

66%
Full breach record for Ransom Memorial Hospital2 incidents on file

Ransom Memorial Hospital (Kansas) reported a phishing incident where 9 employee email accounts were compromised between May 31 and June 11, 2018. Discovered Sept 24, 2018, the breach exposed PHI, SSNs, bank/credit card numbers, driver's licenses, biometric data, and passports for 16,366 individuals (including 1 SC resident). Notifications sent Oct 12, 2018.

Incident timeline

undetected · 116 days
discovery → filing · 25 days

May 31, 2018

Begins

Sep 24, 2018

Discovered

Oct 19, 2018

Filed

vs. sector median

7 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed16,366 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.