HackingStolen CredentialsData ExfiltratedData EncryptedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumActive
Integris Baptist Medical Center, Inc.
bd_d9c4212c6a2ed59f · schema v1 · pii pii-v1
Full breach record for Integris Baptist Medical Center, Inc. →Baptist Medical Center (and Resolute Health Hospital) disclosed a breach affecting patients in Texas. Unauthorized access occurred between March 31 and April 24, 2022, discovered April 20, 2022. Malicious code infected systems; data was exfiltrated. Affected data includes PII (name, DOB, address), SSN, and PHI (medical records, insurance info). No financial account numbers or passwords were compromised. Forensic investigation launched, law enforcement notified, credit monitoring offered.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_66f57573bbab8612Oregon State AGfiled 2022-06-24Verified
- bd_4d2ba2292632fe5bCalifornia State AGfiled 2022-06-15(9d gap)Candidate
- bd_7f5ee3e71988e5a2Washington State AGfiled 2022-06-15(9d gap)Verified
- bd_8c181b3d43ffe625Oregon State AGfiled 2022-06-15(9d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-554593
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 24, 2022
- Raw hash
- 41ef1d50949b7575d42cccffa0325b20c58476223c564dfcd00607c50963ee2e
Reporting entity
- Name
- Integris Baptist Medical Center, Inc.norm: integris baptist medical center
Victim entity
- Name
- Integris Baptist Medical Center, Inc.norm: integris baptist medical center
Incident
- Discovered
- Apr 20, 2022
- Materiality determined
- Jun 15, 2022
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 weeks(65 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.