Compass Health, Inc.
bd_e2ecd01b0f7f3f29 · schema v1 · pii pii-v1
Full breach record for Compass Health, Inc. →Compass Health Network notified Montana AG of a third-party vendor breach involving PaperlessPay. Unauthorized access to PaperlessPay's SQL server occurred on Feb 18, 2020, via stolen credentials. Data potentially exposed included employee names, addresses, SSNs, and masked bank account numbers. Compass Health offered 1 year of credit monitoring. No evidence of confirmed data acquisition, but notice provided as precaution.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 18, 2020
Begins
Mar 20, 2020
Discovered
May 26, 2020
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Massachusetts State AGbd_bce67c6ae78252782020-05-26Verified
- New Hampshire State AGbd_f74ca9da77f4b44b2020-05-27 · +1dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.