Cancer Treatment Centers of America
bd_d32cb69426d4bec8 · schema v1 · pii pii-v1
Full breach record for Cancer Treatment Centers of America →7 incidents on fileCTCA at Southeastern Regional Medical Center notified NH AG of a phishing incident on March 11, 2019. An employee's email was accessed by an unauthorized user between March 10-11, 2019, after providing credentials via a fraudulent email. 20 NH residents affected; data included names, government IDs, medical info, PHI. No SSNs or financial data involved. Forensics retained; passwords reset.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 10, 2019
Begins
Mar 11, 2019
Discovered
May 12, 2019
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Massachusetts State AGbd_4b2273328be2fcbe2019-05-13 · +1dVerified
- Montana State AGbd_1ca373962cb4dd112019-05-10 · +2dVerified
- HHS OCRbd_d8567801696f79062019-05-10 · +2dVerified
- Oregon State AGbd_2439022dedecb8ad2019-05-21 · +9dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing May 10 (MT), last May 21 (OR) — a 11-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.