Sandhills Medical Foundation
bd_b9653a4a741ed836 · schema v1 · pii pii-v1
Full breach record for Sandhills Medical Foundation →2 incidents on fileSandhills Medical Foundation, Inc. notified South Carolina residents of a data breach involving a third-party data storage vendor. Hackers accessed the vendor's system between September 23, 2020, and December 3, 2020, encrypting data and demanding a ransom. The vendor paid the ransom and recovered the data. Affected information included names, dates of birth, addresses, driver's licenses, Social Security numbers, and claims information. Sandhills offered 90 days of identity theft protection via CyberScout.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 23, 2020
Begins
Jan 8, 2021
Discovered
Mar 5, 2021
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Massachusetts State AGbd_08ced65adf490ba92021-03-05Verified
- Maine State AGbd_b0a2d000ebf18e012021-03-05Verified
- HHS OCRbd_ccb15993db7aaf7e2021-03-12 · +7dVerified
- Illinois State AGbd_0c72529b822ca5f92021-01-01 · +63dCandidate
Filing propagation · 5 filings · 4 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Mar 12 (SC) — a 70-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.