Hill Country Memorial Hospital
bd_fc45e4cb92fd18b5 · schema v1 · pii pii-v1
Full breach record for Hill Country Memorial Hospital →Hill Country Memorial Hospital notified patients that an employee's email account was compromised on Feb 21, 2017, likely via phishing, leading to fraudulent invoices. The attacker may have accessed patient PII including names, prescriptions, and financial info. The hospital secured the account, changed passwords, reported to law enforcement, and offered 1 year of Equifax credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 21, 2017
Begins
Feb 21, 2017
Discovered
Apr 25, 2017
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- New Hampshire State AGbd_cd8120be71e54a072017-04-25Verified
- HHS OCRbd_c40bc5f8a50314ea2017-04-21 · +4dVerified
- Massachusetts State AGbd_e6d926b9f934a3f52017-05-02 · +7dVerified
- South Carolina State AGbd_4930c327047117672017-05-22 · +27dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Apr 21 (TX), last May 22 (SC) — a 31-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.