DisclosureLens
HackingHealthcareHealthcareSupply Chain (3P Vendor)Employee Data InvolvedDelayed DiscoveryPIIIdentity (basic)Government IDFinancial accountEmploymentMediumContained

Community Memorial Health System

bd_5b3d82eb2f92ba2a · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Apr 27, 2020

To disclose

Affected

Not disclosed

Confidence

76%
Full breach record for Community Memorial Health System6 incidents on file

Community Memorial Health System (CMHS) notified employees of a data breach at third-party vendor PaperlessPay Corporation. DHS alerted PaperlessPay on February 19, 2020 that an unknown individual was selling access to their client database on the dark web. The unauthorized person accessed PaperlessPay's SQL server on February 18, 2020, where CMHS employee pay stub and tax form data was stored, including names, addresses, SSNs, pay/withholdings, and in some cases bank account numbers. CMHS offered one year of free Experian IdentityWorks to affected employees.

Incident timeline

Feb 18, 2020

Begins

Apr 27, 2020

Filed

Part of PaperlessPay Corporation supply-chain incident (2020) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.