DisclosureLens
Social EngineeringHealthcareHealthcarePhishingCustomer Data InvolvedEmployee Data InvolvedPHIHealth (basic)Identity (basic)Government IDMediumContained

Community Memorial Health System

bd_5f791db51475fcd1 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jun 23, 2017

Filed

Sep 5, 2017

To disclose

11 weeks

Affected

Not disclosed

Linked

2 filings

Confidence

65%
Full breach record for Community Memorial Health System6 incidents on file

Community Memorial Health System reported that an employee's email account was compromised via a phishing email on June 22, 2017. The employee noticed anomalies on June 23, 2017, leading to a password reset and investigation. The compromised account contained patient names, medical record numbers, dates of service, and certain health information. Some records may have included Social Security Numbers. Forensic analysis indicated it is highly unlikely personal information was accessed, but notice was provided as a precaution. Credit monitoring was offered.

Incident timeline

undetected · 1 days
discovery → filing · 11 weeks / 74 days

Jun 22, 2017

Begins

Jun 23, 2017

Discovered

Sep 5, 2017

Filed

vs. sector median

2 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings

View merged incident ↗
HHS OCRSep 5 · first
California State AGSep 5 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.