GUIDEHOUSE INC.
bd_a1315e93704516aa · schema v1 · pii pii-v1
Full breach record for GUIDEHOUSE INC. →2 incidents on fileGuidehouse, a business associate, reported a cyber-attack on its secure file transfer device that affected 91,331 individuals. The breach, reported to HHS on 2021-07-15, compromised protected health information including names, dates of birth, diagnoses, conditions, and claims information. In response, Guidehouse applied a critical patch to mitigate the vulnerability, discontinued the compromised device, and transitioned to a different network.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Jul 15, 2021
Filed
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Montana State AGbd_466ff546cdc0a84a2021-07-29 · +14dCandidate
- Massachusetts State AGbd_0708f8c7afa7fc0a2021-06-28 · +17dVerified
- Montana State AGbd_450f31b4b76577de2021-06-25 · +20dCandidate
Filing propagation · 4 filings · 3 states
View merged incident ↗Pattern: first filing Jun 25 (MT), last Jul 29 (MT) — a 34-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.