DisclosureLens
HackingHealthcareHealthcareStolen CredentialsCustomer Data InvolvedDelayed DiscoveryIdentity (basic)LowContained

Moffitt Cancer Center and Research Institute

bd_fc2e5eb7425bb60d · schema v1 · pii pii-v1

Severity

Low

Discovered

Oct 26, 2023

Filed

Apr 24, 2024

To disclose

26 weeks

Affected

1state residents only

Linked

6 filings

Confidence

66%
Full breach record for Moffitt Cancer Center and Research Institute5 incidents on file

Advarra, Inc, on behalf of Moffitt Cancer Center, notified patients and research participants of a data security incident where an unauthorized third party accessed a single employee account on October 25, 2023. The incident involved names of individuals. Advarra contained the incident on October 26, 2023, engaged cybersecurity experts, and offered 24 months of identity monitoring via Kroll.

Incident timeline

undetected · 1 days
discovery → filing · 26 weeks / 181 days

Oct 25, 2023

Begins

Oct 26, 2023

Discovered

Apr 24, 2024

Filed

vs. sector median

+13 wks slower

This filing is one of 6 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (5) · sorted by filing gap

Show 1 more filingup to 23d gap

Filing propagation · 6 filings · 6 states

View merged incident ↗
Illinois State AGApr 1 · first
Montana State AG+23d · this page

Pattern: first filing Apr 1 (IL), last Apr 25 (MA) — a 24-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.