DisclosureLens
OHIOHackingHealthcareHealthcareCustomer Data InvolvedIdentity (basic)Government IDHealth (basic)HighResolved

Greater Cincinnati Behavioral Health

bd_a0db490ef29f1fdb · schema v1 · pii pii-v1

Severity

High

Discovered

Dec 10, 2023

Filed

Feb 2, 2024

To disclose

Affected

50,000

Linked

6 filings

Confidence

95%
Full breach record for Greater Cincinnati Behavioral Health

Greater Cincinnati Behavioral Health Services (OH) reported to HHS on 2024-02-02 a Hacking/IT Incident affecting 50,000 individuals (60,796 per the web description). Breached information located on a Network Server. PHI involved included names, addresses, dates of birth, Social Security numbers, diagnoses, conditions, lab results, medications, and other treatment information. The CE notified affected individuals, the media, and HHS, and implemented additional administrative, technical, and security safeguards.

Leak gap clock Leak >30d
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

discovery → filing · 8 weeks / 54 days

Dec 10, 2023

Discovered

Feb 2, 2024

Filed

This filing is one of 6 about the same incident.View merged incident
A leak claim by dragonforce about this victim predates this filing by 51 days.View originating leak claim

Linked disclosures

Why this link?

Ransomware claims (1)

Regulatory filings (4) · sorted by filing gap

Filing propagation · 5 filings · 4 states

View merged incident ↗
Indiana State AGJan 25 · first
HHS OCR+8d · this page

Pattern: first filing Jan 25 (IN), last Sep 11 (ME) — a 230-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.