Hill Country Memorial Hospital
bd_c40bc5f8a50314ea · schema v1 · pii pii-v1
Full breach record for Hill Country Memorial Hospital →Hill Country Memorial Hospital (TX) reported to HHS on 2017-04-21 a Hacking/IT Incident affecting 8,449 individuals. On February 21, 2017, a workforce member responded to a phishing email and provided credentials, enabling an unknown external actor to access her email account and send fraudulent invoices. Breached PHI on Email servers may have included names, addresses, dates of birth, Social Security numbers, and medical information. The CE notified HHS, affected individuals, and media, and implemented security awareness training and email controls. OCR obtained assurances of corrective action.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 21, 2017
Begins
Feb 21, 2017
Discovered
Apr 21, 2017
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- New Hampshire State AGbd_cd8120be71e54a072017-04-25 · +4dVerified
- Montana State AGbd_fc45e4cb92fd18b52017-04-25 · +4dCandidate
- Massachusetts State AGbd_e6d926b9f934a3f52017-05-02 · +11dVerified
- South Carolina State AGbd_4930c327047117672017-05-22 · +31dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Apr 21 (TX), last May 22 (SC) — a 31-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.