Confluence Health
ent_becb9ae558cabce2be6a1bad
Disclosures
2
State AG · HHS OCR · 1 jurisdiction
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
33,821
nationwide · HHS OCR WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Confluence Health
- Normalized
- confluence health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (2)newest first
- Washington State AGas victim2020-08-14
Confluence Health Foundation reported a ransomware incident affecting its third-party vendor, Blackbaud, Inc. Unauthorized access occurred between April 18 and May 7, 2020, resulting in the exfiltration of donor names and dates of birth. The incident was discovered on July 16, 2020, and 1,132 Washington residents were notified on August 14, 2020.
- WASHINGTONHHS OCRas victim2018-07-27
Confluence Health (WA) reported to HHS on 2018-07-27 a Hacking/IT Incident affecting 33,821 individuals. A Confluence Health employee received and responded to a phishing email on March 29, 2018. An unauthorized external actor accessed the employee's email account from a Nigerian internet address on March 30 and again on May 28, 2018, sent phishing emails to multiple recipients, and auto-deleted sent emails. The account contained PHI including ~32,821 patients' names and treatment information. Breached information located on Email. OCR provided technical assistance on the CE's security management process.