DisclosureLens
GEORGIASocial EngineeringHealthcareHealthcarePhishingStolen CredentialsCustomer Data InvolvedData ExfiltratedTargetedHealth (basic)Identity (basic)Government IDHighResolved

AU MEDICAL CENTER, INC.

bd_eb79092ade2c98ae · schema v1 · pii pii-v1

Severity

High

Discovered

Filed

May 26, 2017

To disclose

Affected

5,600

Linked

2 filings

Confidence

97%
Full breach record for AU MEDICAL CENTER, INC.3 incidents on file

On September 7, 2016, a cyber-attacker sent a phishing email to Augusta University Medical Center, Inc. (GA) and obtained employee usernames and passwords. The attacker accessed a self-service portal to redirect employee paychecks. PHI of 4,690 individuals was exposed, including addresses, dates of birth, medical record numbers, insurance, prescription and treatment information, and, for some, Social Security numbers. HHS breach submission filed 2017-05-26; 5,600 individuals listed as affected. Breached information located in Email.

HIPAA clock HHS notified
no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.

Incident timeline

Sep 7, 2016

Begins

May 26, 2017

Filed

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
New Hampshire State AGMay 26 · first
HHS OCRMay 26 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.