Southwest Healthcare Services
bd_d333197f85b58141 · schema v1 · pii pii-v1
Full breach record for Southwest Healthcare Services →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Donutleaks on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Southwest Healthcare Services is a non-profit organization dedicated to providing quality healthcare in southwest North Dakota and northwest South Dakota. https://swhealthcare.net/ Full Data Download...
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Oct 22, 2022
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Illinois State AGbd_698e75070d75b0d32023-01-01 · +71dVerified by operator
- Washington State AGbd_0c8778d9b0a5454d2023-03-31 · +160dVerified by operator
- Montana State AGbd_3e7012f6243e4f0d2023-03-31 · +160dVerified by operator
- Vermont State AGbd_77a08581489e18ad2023-03-31 · +160dVerified by operator
Show 2 more filings ↓Show fewer ↑up to 161d gap
- Vermont State AGbd_c057300c877b220e2023-03-31 · +160dVerified by operator
- HHS OCRbd_b9a3d1a0f4aeea7d2023-04-01 · +161dVerified
Filing propagation · 7 filings · 5 states
View merged incident ↗Pattern: first filing Oct 22, last Apr 1 (ND) — a 161-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
donutleaks
According to ransomware.live, Donut Leaks (D0nut) is a data-extortion group active since August 2022 that developed its own ransomware encryptor, linked to attacks on Greece's DESFA gas company and Continental, believed to be an affiliate of multiple RaaS operations who pivoted to running an independent extortion platform.