Confluence Health
ent_becb9ae558cabce2be6a1bad
Disclosures
2
State AG · HHS OCR · 1 jurisdiction
Incidents
—
no linked incident in sample
Max affected reported
33,821
as filed · HHS OCR WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Confluence Health
- Normalized
- confluence health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (2)newest first
- 🌲Washington State AGas victim2020-08-14
Confluence Health Foundation, a health sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2020-07-16 and filed notice on 2020-08-14. 1,132 Washington residents were affected. 29 days elapsed between awareness and notification. 160 days to identify the breach. 0 days to contain the breach.
- WASHINGTONHHS OCRas victim2018-07-27
Confluence Health (WA) reported to HHS on 2018-07-27 a Hacking/IT Incident affecting 33,821 individuals. A Confluence Health employee received and responded to a phishing email on March 29, 2018. An unauthorized external actor accessed the employee's email account from a Nigerian internet address on March 30 and again on May 28, 2018, sent phishing emails to multiple recipients, and auto-deleted sent emails. The account contained PHI including ~32,821 patients' names and treatment information. Breached information located on Email. OCR provided technical assistance on the CE's security management process.