Children's Mercy Kansas City
bd_5dfb7d56d9364c3e · schema v1 · pii pii-v1
Children's Mercy Kansas City notified patients and staff of a phishing incident affecting five employee email accounts between Dec 2017 and Jan 2018. Unauthorized access led to the download of mailbox contents, exposing PHI and PII (names, MRNs, DOB, etc.) of potentially affected patients. The company reset accounts, engaged forensic experts, and provided 12 months of identity protection.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 2, 2017
Begins
Dec 2, 2017
Discovered
Apr 30, 2018
Filed
vs. sector median
+10 wks slower
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- New Hampshire State AGbd_2cce272c9ebd9b312018-04-30Verified
- Massachusetts State AGbd_a929487dab3c7ff12018-04-30Verified
Filing propagation · 3 filings · 3 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.