DisclosureLens
HackingHealthcareHealthcareSupply Chain (3P Vendor)Customer Data InvolvedData DestroyedPHIIdentity (basic)Government IDHealth (basic)FinancialMediumContained

Wolfe Clinic

bd_f172872cc498a4c4 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Dec 4, 2021

Filed

Sep 19, 2022

To disclose

41 weeks

Affected

Not disclosed

Confidence

65%
Full breach record for Wolfe Clinic →5 incidents on file

Wolfe Clinic, P.C. notified patients that their data may have been exposed due to a security incident at their third-party vendor, Eye Care Leaders, on December 4, 2021. An unauthorized party accessed the myCare Integrity platform and deleted databases and system configuration files. Eye Care Leaders stopped the access immediately. While there was no evidence that Wolfe Clinic's patient records were accessed, the possibility of exposure of PHI and PII (including SSNs) could not be ruled out. Identity monitoring services were offered.

Incident timeline

discovery → filing · 41 weeks / 289 days

Dec 4, 2021

Begins

Dec 4, 2021

Discovered

Sep 19, 2022

Filed

vs. sector median

+32 wks slower

Part of Eye Care Leaders supply-chain incident (2022) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.