Saint Alphonsus Health System
bd_59ef7b672a01c380 · schema v1 · pii pii-v1
Full breach record for Saint Alphonsus Health System →Saint Alphonsus Health System (ID) reported to HHS on 2021-03-04 a Hacking/IT Incident (email phishing) affecting 134,906 individuals. An employee was the victim of a phishing scheme exposing ePHI including names, addresses, dates of birth, SSNs, health insurance, claims and financial information, lab results, and medications. Breached information located in Email systems. No business associate was involved. OCR provided technical assistance; the CE retrained staff and implemented additional safeguards.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Mar 4, 2021
Filed
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- California State AGbd_8ed3b86c841639cb2021-03-04Verified
- Oregon State AGbd_bd2986380c1ca3292021-03-04Verified
- Illinois State AGbd_beca9b514c566ae82021-01-01 · +62dCandidate
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Mar 4 (ID) — a 62-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.