Crestwyn Behavioral Health Hospital, Inc.
bd_efe9ab8442feefc4 · schema v1 · pii pii-v1
Full breach record for Crestwyn Behavioral Health Hospital, Inc. →Crestwyn Behavioral Health Hospital, Inc. (TN) reported to HHS on 2024-05-31 a Hacking/IT Incident (email phishing) affecting 1,757 individuals. An employee was the subject of an email phishing scheme, exposing PHI including names, addresses, and treatment and health insurance information. Breached information located on Email. The CE notified HHS, affected individuals, and the media, posted a substitute breach notice, and implemented improved technical safeguards.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
May 31, 2024
Filed
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.