KYHackingHealthcareHealthcareBusiness Associate (HIPAA)Customer Data InvolvedData ExfiltratedPHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTHighContained
Waystar
bd_7b66f4b383a8c41d · schema v1 · pii pii-v1
Full breach record for Waystar →Waystar Health reported to HHS on 2020-08-25 a Hacking/IT Incident affecting 1021 individuals. Breached information located on Network Server. The BA reported that ePHI of 1,021 individuals was viewable via the Internet, including names, dates of birth, addresses, Social Security numbers, and diagnoses/conditions. The BA notified HHS, affected individuals, the media, and posted substitute notice to its website. Upon discovering this incident, the BA implemented new administrative and technical safeguards to better protect sensitive data.
HIPAA clock✓ HHS notified≤1 day discovery → filing
⚠ filing dateThe stored discovery date equals the regulator filing date, so no genuine detection date was captured.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,021 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Aug 25, 2020
- Raw hash
- 7de7d61a5abbad4f2af15dd88e879511967baffa63e702fe40c9f9887a52f2f2
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Waystarnorm: waystar
- Domain
- waystar.com
- Industry
- Health Care Services
Victim entity
- Name
- Waystarnorm: waystar
- Domain
- waystar.com
- Industry
- Healthcaresource default
Incident
- Discovered
- Aug 25, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,021
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Waystar Healthbusiness associate
Compliance
- Time to disclose
- ≤1 day(0 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- filing dateThe stored discovery date equals the regulator filing date, so no genuine detection date was captured.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Aug 25, 2020→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.