Community Memorial Health System
bd_5b3d82eb2f92ba2a · schema v1 · pii pii-v1
Full breach record for Community Memorial Health System →6 incidents on fileCommunity Memorial Health System (CMHS) notified employees of a data breach at third-party vendor PaperlessPay Corporation. DHS alerted PaperlessPay on February 19, 2020 that an unknown individual was selling access to their client database on the dark web. The unauthorized person accessed PaperlessPay's SQL server on February 18, 2020, where CMHS employee pay stub and tax form data was stored, including names, addresses, SSNs, pay/withholdings, and in some cases bank account numbers. CMHS offered one year of free Experian IdentityWorks to affected employees.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 18, 2020
Begins
Apr 27, 2020
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.