DisclosureLens
Social EngineeringHealthcareHealthcarePhishingData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPHIHealth (basic)Identity (basic)MediumContained

Spokane Regional Health District

bd_87a3ffcfaa82cd97 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Feb 24, 2022

Filed

Mar 21, 2022

To disclose

25 days

Affected

1,260state residents only

Confidence

69%
Full breach record for Spokane Regional Health District2 incidents on file

Spokane Regional Health District (SRHD) reported a phishing incident affecting 1,260 Washington residents. On Feb 23, 2022, an employee clicked a malicious link, compromising Office 365 credentials. SRHD discovered the breach on Feb 24, 2022, and notified the WA Attorney General on March 21, 2022. Affected PHI included names, DOB, and medical details. SRHD reset credentials, provided training, and notified affected individuals.

Washington clock WA AG ≤30d25 days discovery → filing

Incident timeline

undetected · 1 days
discovery → filing · 25 days

Feb 23, 2022

Begins

Feb 24, 2022

Discovered

Mar 21, 2022

Filed

vs. sector median

7 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,260 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.