BAYSTATE HEALTH, INC.
bd_abbaaee49c17c695 · schema v1 · pii pii-v1
Full breach record for BAYSTATE HEALTH, INC. →4 incidents on fileBaystate Health notified the NH Attorney General of a phishing incident between Feb 7 and Mar 7, 2019, resulting in unauthorized access to employee email accounts. One New Hampshire resident's PHI, including name, address, DOB, SSN, Medicare number, and health information, was potentially exposed. Baystate secured accounts, engaged forensics, and offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 7, 2019
Begins
Feb 7, 2019
Discovered
Apr 8, 2019
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- HHS OCRbd_d91c1523d2b37e8f2019-04-05 · +3dVerified
- Illinois State AGbd_a601a44e01784bd12019-01-01 · +97dCandidate
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Apr 8 (NH) — a 97-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.