DisclosureLens
Social EngineeringHealthcareHealthcarePhishingMulti-Stage ChainCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Health (basic)PHILowActive

Children's Mercy Kansas City

bd_5dfb7d56d9364c3e · schema v1 · pii pii-v1

Severity

Low

Discovered

Dec 2, 2017

Filed

Apr 30, 2018

To disclose

21 weeks

Affected

3state residents only

Linked

3 filings

Confidence

65%

Children's Mercy Kansas City notified patients and staff of a phishing incident affecting five employee email accounts between Dec 2017 and Jan 2018. Unauthorized access led to the download of mailbox contents, exposing PHI and PII (names, MRNs, DOB, etc.) of potentially affected patients. The company reset accounts, engaged forensic experts, and provided 12 months of identity protection.

Incident timeline

discovery → filing · 21 weeks / 149 days

Dec 2, 2017

Begins

Dec 2, 2017

Discovered

Apr 30, 2018

Filed

vs. sector median

+10 wks slower

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
New Hampshire State AGApr 30 · first
Massachusetts State AGApr 30 · first
Montana State AGApr 30 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.