BANNER HEALTH
bd_ac773cf578b8482a · schema v1 · pii pii-v1
Full breach record for BANNER HEALTH →2 incidents on fileBanner Health disclosed a cyber attack where attackers gained unauthorized access to patient, provider, and payment card data. The attack began on June 17, 2016, and was discovered in two phases: payment card systems on July 7, 2016, and patient/provider servers on July 13, 2016. Approximately 3.7 million individuals were affected. Data exposed included PHI, SSNs, and payment card details. Banner Health engaged forensics, blocked attackers, and offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Jun 17, 2016
Begins
Jul 13, 2016
Discovered
Aug 3, 2016
Filed
vs. sector median
9 wks faster
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Washington State AGbd_0588cdfba1eacf3d2016-08-03Candidate
- New Hampshire State AGbd_47377d5f3cbb422e2016-08-03Verified
- Montana State AGbd_84becbd39b03c2c22016-08-03Verified
- Massachusetts State AGbd_ac336604b83cc8692016-08-03Verified
Show 2 more filings ↓Show fewer ↑
- Oregon State AGbd_cb3e26b4ba0ad5cc2016-08-03Verified
- HHS OCRbd_efb36ded28ef2d7d2016-08-03Verified
Filing propagation · 7 filings · 7 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.