UnityPoint Health
bd_fb9da4101eacad04 · schema v1 · pii pii-v1
Full breach record for UnityPoint Health →14 incidents on fileUnityPoint Health disclosed a phishing attack that compromised employee email accounts between March 14 and April 3, 2018. The incident was discovered on May 31, 2018. Attackers used fraudulent emails to trick employees into providing credentials, gaining access to protected health information and personal data including SSNs and financial account numbers. The attack was financially motivated, likely aimed at diverting funds, though patient data was exposed. UnityPoint reset passwords, implemented MFA, and offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 14, 2018
Begins
May 31, 2018
Discovered
Jul 30, 2018
Filed
vs. sector median
2 wks faster
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Massachusetts State AGbd_001ef817a39f7b6d2018-07-30Verified
- Montana State AGbd_38c797e4e7408ca32018-07-30Verified
- HHS OCRbd_799993f34d0de7d62018-07-30Verified
- New Hampshire State AGbd_911dab7665ebb5b62018-07-30Verified
Show 1 more filing ↓Show fewer ↑
- Montana State AGbd_f8f71ff026792fff2018-07-30Verified
Filing propagation · 6 filings · 5 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.