Direct Scripts
bd_e82d53d6b7c0ccd6 · schema v1 · pii pii-v1
Full breach record for Direct Scripts →Direct Scripts notified Montana residents of a ransomware attack on January 30, 2019, that encrypted a server storing patient records. Potentially affected data included names, addresses, and prescription information (PHI). No SSN or credit card data was stored on the server. The company engaged forensic investigators and provided identity protection services.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 30, 2019
Discovered
Feb 22, 2019
Filed
vs. sector median
9 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- New Hampshire State AGbd_e65e13dc09abc6012019-02-22Verified
- HHS OCRbd_673e0645e872913e2019-03-06 · +12dVerified
- Illinois State AGbd_6fee2b723be32d612019-01-01 · +52dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Mar 6 (OH) — a 64-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.