Capital Region Medical Center
bd_c8480a3cbc771a48 · schema v1 · pii pii-v1
Full breach record for Capital Region Medical Center →Capital Region Medical Center (CRMC) disclosed that on December 17, 2021, an unauthorized third party gained access to files containing personal and health information of CRMC employees. Data included names, DOB, addresses, medical info, health insurance info, SSNs, and driver's license numbers. CRMC disabled its network, engaged a cybersecurity firm, notified law enforcement, and offered one year of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 17, 2021
Begins
Dec 17, 2021
Discovered
Mar 25, 2022
Filed
vs. sector median
+2 wks slower
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- New Hampshire State AGbd_32f439e24ceb5bee2022-03-25Verified
- Maine State AGbd_9adc7a8104cf5c602022-03-25Verified
- Indiana State AGbd_6299b52aa0fbf0cf2022-03-24 · +1dVerified by operator
- Massachusetts State AGbd_e52487bfa623bfbc2022-03-30 · +5dCandidate
Show 1 more filing ↓Show fewer ↑up to 14d gap
- HHS OCRbd_7ab7349dfcd1fd472022-03-11 · +14dVerified by operator
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Mar 11 (MO), last Mar 30 (MA) — a 19-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.