DisclosureLens
Social EngineeringHealthcareEducationHealthcarePhishingCustomer Data InvolvedEmployee Data InvolvedPHIHealth (basic)Government IDFinancial accountMediumContained

Hilltop Community Resources Residential Youth Services

bd_e25d4e9ad701d860 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Aug 23, 2019

Filed

Dec 13, 2019

To disclose

16 weeks

Affected

1state residents only

Confidence

66%

Hilltop Community Resources Residential Youth Services notified Montana residents of a phishing incident discovered on August 23, 2019, which compromised employee email accounts containing PHI, SSNs, and health insurance info. The company engaged forensic investigators, offered one year of Kroll identity monitoring, and implemented MFA and staff training.

Incident timeline

discovery → filing · 16 weeks / 112 days

Aug 23, 2019

Discovered

Dec 13, 2019

Filed

vs. sector median

+4 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.