DisclosureLens
ILLINOISHackingHealthcareHealthcareVulnerability ExploitBusiness Associate (HIPAA)Customer Data InvolvedData ExfiltratedHealth (basic)Identity (basic)Financial accountMedium

Blackhawk Statement Group

bd_73f1a0701137b0cb · schema v1 · pii pii-v1

Severity

Medium

Discovered

Aug 22, 2013

Filed

Oct 9, 2013

To disclose

7 weeks

Affected

7,120

Confidence

50%
Full breach record for Blackhawk Statement Group

BlackHawk, a business associate, reported to HHS on 2013-10-09 a hacking incident affecting 7,120 individuals. The incident, which occurred on June 30, 2013, involved the hacking of a payment portal. The breach exposed names, addresses, email addresses, and credit card information. The software vulnerability that was exploited has since been patched.

HIPAA clock HHS report on time7 weeks discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

undetected · 53 days
discovery → filing · 7 weeks / 48 days

Jun 30, 2013

Begins

Aug 22, 2013

Discovered

Oct 9, 2013

Filed

vs. sector median

5 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed7,120 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.