GreyHealth Group
bd_7acafbed1ef56764 · schema v1 · pii pii-v1
Full breach record for GreyHealth Group →GreyHealth Group notified the NH AG that an employee sent 2017 W2 forms (containing SSNs, names, addresses, salaries) to an unauthorized recipient on Jan 26, 2018, after being targeted by a phishing scam. The company discovered the incident on Feb 6, 2018. Approximately 683 US employees were affected, including 1 NH resident. The company offered 2 years of credit monitoring via Experian.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 26, 2018
Begins
Feb 6, 2018
Discovered
Mar 1, 2018
Filed
vs. sector median
11 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.