Cancer Treatment Centers of America
bd_d8567801696f7906 · schema v1 · pii pii-v1
Full breach record for Cancer Treatment Centers of America →7 incidents on fileCancer Treatment Centers of America (CTCA) at Southeastern Regional Medical Center (GA) reported to HHS OCR on 2019-05-10 a Hacking/IT Incident affecting 16,819 individuals. Several employees were victims of an email phishing scheme that compromised ePHI including names, Social Security numbers, addresses, dates of birth, financial information, health insurance information, and clinical information. Breached information was located in Email. The CE notified HHS, affected individuals, and the media, and implemented additional technical safeguards and employee retraining. OCR obtained corrective action assurances.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
May 10, 2019
Filed
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Montana State AGbd_1ca373962cb4dd112019-05-10Verified
- New Hampshire State AGbd_d32cb69426d4bec82019-05-12 · +2dVerified
- Massachusetts State AGbd_4b2273328be2fcbe2019-05-13 · +3dVerified
- Oregon State AGbd_2439022dedecb8ad2019-05-21 · +11dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing May 10 (MT), last May 21 (OR) — a 11-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.