Boulder Neurosurgical and Spine Associates
bd_da518c6e8335a2af · schema v1 · pii pii-v1
Full breach record for Boulder Neurosurgical and Spine Associates →Boulder Neurosurgical and Spine Associates reported to HHS on 2021-11-29 a Hacking/IT Incident affecting 21,450 individuals. Breached information located on Email. An employee was the victim of an email phishing attack which affected the protected health information (PHI) of 21,450 individuals. The PHI involved included names, dates of birth, diagnoses, lab results, medications prescribed, and other treatment information. The CE closed its business; the investigation was subsequently closed.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Nov 29, 2021
Filed
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- New Hampshire State AGbd_a4f5395f3b6e85482021-12-02 · +3dVerified
- Montana State AGbd_5c38e2e8db59427d2021-11-24 · +5dCandidate
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Nov 24 (MT), last Dec 2 (NH) — a 8-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.