Quality Behavioral Health
bd_aba9a7623559f197 · schema v1 · pii pii-v1
Full breach record for Quality Behavioral Health →Quality Behavioral Health (Washington) reported to HHS OCR on 2022-12-26 a ransomware attack affecting 3,498 individuals. Breached information was located on a Network Server and included names, Social Security numbers, driver's license/state ID numbers, financial information, dates of birth, diagnoses, health insurance information, and other treatment information. The CE notified HHS, affected individuals, and the media, posted substitute notice on its website, and provided credit monitoring and identity theft protection services. Technical safeguards were implemented in response.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Dec 26, 2022
Filed
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Montana State AGbd_8e5964c690d1b6ed2023-01-25 · +30dCandidate
- Washington State AGbd_ecaae56dffbc669f2023-01-25 · +30dVerified
Filing propagation · 3 filings · 2 states
View merged incident ↗Pattern: first filing Dec 26 (WA), last Jan 25 (WA) — a 30-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.