NEIGHBORHOOD HEALTHCARE
bd_8aaf06ac833493f3 · schema v1 · pii pii-v1
Full breach record for NEIGHBORHOOD HEALTHCARE →3 incidents on fileNeighborhood Healthcare notified patients and employees of a ransomware attack on its third-party hosting provider, Netgain. The attacker gained unauthorized access to Netgain's environment starting November 24, 2020, and launched a ransomware attack on December 3, 2020, encrypting files. Netgain paid a ransom to the attacker. Neighborhood Healthcare learned of the attack on December 3, 2020, and confirmed on March 16, 2021, that patient PHI (including SSNs, names, DOBs, treatment info) and employee data (including SSNs, retirement info) were impacted. The organization engaged outside experts, transitioned hosting providers, and offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 24, 2020
Begins
Dec 3, 2020
Discovered
Apr 8, 2021
Filed
vs. sector median
+5 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Montana State AGbd_2ef8bb246b7050442021-04-08Candidate
- Indiana State AGbd_b955947cb8fc4eec2021-04-08Verified
- New Hampshire State AGbd_bb6f3e4aec00ab002021-04-09 · +1dVerified
- HHS OCRbd_57b894cf856fcd162021-04-14 · +6dVerified
Filing propagation · 5 filings · 4 states
View merged incident ↗Pattern: first filing Apr 8 (MT), last Apr 14 (CA) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.