DisclosureLens
Social EngineeringHealthcareHealthcarePhishingStolen CredentialsData ExfiltratedTargetedIdentity (basic)Government IDHealth (basic)Financial accountCredentialsMediumContained

Atrium Health Foundation

bd_b758586ed2e02128 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Apr 29, 2024

Filed

Sep 13, 2024

To disclose

20 weeks

Affected

1state residents only

Linked

3 filings

Confidence

66%
Full breach record for Atrium Health Foundation6 incidents on file

Atrium Health notified affected individuals in Montana and other states that an unauthorized third party gained access to employee email accounts via phishing on April 29, 2024. The incident may have exposed personal, health, and financial information. Atrium Health engaged forensic consultants, notified law enforcement, secured accounts, and offered 24 months of Kroll identity monitoring.

Incident timeline

discovery → filing · 20 weeks / 137 days

Apr 29, 2024

Begins

Apr 29, 2024

Discovered

Sep 13, 2024

Filed

vs. sector median

+8 wks slower

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Illinois State AGSep 1 · first
Montana State AG+12d · this page

Pattern: first filing Sep 1 (IL), last Sep 13 (MT) — a 12-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.