DisclosureLens
NORTH CAROLINAHackingHealthcareHealthcarePhishingStolen CredentialsCustomer Data InvolvedData ExfiltratedPHIHealth (basic)Identity (basic)Government IDFinancial accountHighContained

Morehead Memorial Hospital

bd_84856a782283f7b5 · schema v1 · pii pii-v1

Severity

High

Discovered

Jun 1, 2017

Filed

Sep 15, 2017

To disclose

15 weeks

Affected

66,000

Linked

2 filings

Confidence

67%
Full breach record for Morehead Memorial Hospital

Morehead Memorial Hospital reported to HHS on 2017-09-15 a Hacking/IT Incident affecting 66,000 individuals. Breached information located on Email. Phishing emails compromised employee accounts, exposing PHI including treatment, payment, names, and SSNs for 1,200 individuals. Navigant Consulting investigated. Remediation included password resets, enhanced training, and internal reporting tools.

HIPAA clockDiscovered Jun 1, 2017Notified Sep 15, 2017106d HHS report late15 weeks discovery → filing
occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.

Incident timeline

discovery → filing · 15 weeks / 106 days

Jun 1, 2017

Begins

Jun 1, 2017

Discovered

Sep 15, 2017

Filed

vs. sector median

+3 wks slower

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Montana State AGSep 15 · first
HHS OCRSep 15 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.