Medical College of Wisconsin
bd_9b1983e1d1c78a7a · schema v1 · pii pii-v1
Medical College of Wisconsin notified patients of a spear phishing attack targeting employee email accounts. Unauthorized access occurred July 21-28, 2017. Compromised accounts contained PHI including names, DOBs, addresses, medical record numbers, and insurance info. No SSNs were involved. Forensic investigation confirmed the scope.
J jump to incidentP pin to compareR raw source
Incident timeline
Jul 21, 2017
Begins
Jul 21, 2017
Discovered
Nov 17, 2017
Filed
vs. sector median
+6 wks slower
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- California State AGbd_5ca941b7c82c93472017-11-17Candidate
- Massachusetts State AGbd_fd11ef3201a810082017-11-20 · +3dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.