INOVA HEALTH SYSTEM FOUNDATION
bd_cf1753ab447b5254 · schema v1 · pii pii-v1
Full breach record for INOVA HEALTH SYSTEM FOUNDATION →6 incidents on fileInova Health System (VA, Healthcare Provider) reported to HHS OCR on 2020-09-09 that its business associate experienced a ransomware attack on a network server affecting the ePHI of approximately 1,045,270 individuals. Exposed data included names, addresses, dates of birth, and treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Sep 9, 2020
Filed
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Washington State AGbd_e64407193b9828fb2020-09-09Verified
- California State AGbd_4cea0b8a1367835a2020-09-15 · +6dVerified
- Oregon State AGbd_c39af1065b9670912020-09-22 · +13dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Sep 9 (WA), last Sep 22 (OR) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.