DisclosureLens

Incident evidence package

The incident, as filed. Signed.

A signed PDF assembling every regulatory filing linked to one breach incident into a single timestamped record — the facts as filed, with the provenance of every value. It reports filed facts; it draws no legal characterization.

Opening page of a signed evidence package for Change Healthcare Inc.: KPI grid showing 12 linked regulatory filings, 0 unverified claims, 10 jurisdictions filed, the affected-individual total as filed, and a 207-day filing span
The opening page of a real package — Change Healthcare, twelve regulatory filings across ten jurisdictions, 207 days of filing activity. Unverified claims are counted apart from filings, and the affected-individual total is stated the way the regulators received it. See this exact package’s record →

$79 one-time, per incident — no account required — or included in the casework plan.

Every confirmed incident’s record carries its package. No account required — the download link arrives in your browser and by email, and stays valid for 12 months. Payment is handled by Stripe.

The package freezes at first download — later changes to the live record do not change the document you bought.

What the package contains

Sixteen sections, from the opening KPI grid to the chain-of-custody appendix. Sections with nothing recorded say so — an explicit “none recorded” line, never a silent omission.

  • Every linked filing. Each regulatory filing linked to the incident — source, jurisdiction, filed date, and the linkage method and confidence that placed it there.
  • Litigation timeline and notification clocks. Chronological events reconstructed from the filings, recorded intervals between them, and each statutory notification clock with its recorded start, deadline, day basis, and status.
  • Cross-filing comparison. The same incident as reported to different regulators, side by side — recorded differences between commensurable fields, scope revisions, and supplemental or amended filings.
  • Chain-of-custody appendix. Per filing: the source URL, fetch timestamp, SHA-256 of the bytes as fetched, immutable storage key, and the extraction model and prompt version that produced the structured record.
  • Signed and tamper-evident. PAdES-B signature with byte-range tamper detection; the signer certificate fingerprint is printed in the footer so the document verifies independently of us.

Inside a real package

Unedited crops from packages generated against the live record. The largest current package assembles 77 regulatory filings from a single vendor breach into one document.

The litigation timeline reconstructs the incident from the filings themselves — who was told what, when, in which venue.

Litigation timeline table from an evidence package: dated events from press report through SEC 8-K, HHS OCR, and state attorney general filings, each with its source and record id
CareCloud, 2026 — press report, SEC 8-K discovery and materiality determination, then HHS OCR and four state attorneys general. Every event dated, sourced, and tied to its record id. See this exact package’s record →

Each statutory notification clock is computed from recorded dates and shown with its inputs — including how well-grounded the start date is.

Regulatory notification clocks table: state statutes with recorded start dates, windows, deadlines, day bases, provenance grades, and past-deadline badges
Young Consulting — Maine, Vermont, Washington, California, and Maryland clocks on one incident: statute, recorded start, window, deadline, elapsed days, calendar-vs-business day basis, and the provenance of the date each clock runs from. See this exact package’s record →

Regulators hear different numbers. The cross-filing comparison puts every filing's figures side by side and labels each one's scope.

Cross-filing comparison table: the same incident filed with seven regulators, showing state counts, nationwide counts, scope labels, and discovery dates side by side
The same breach as filed with seven regulators: state-resident counts beside nationwide counts, scope labels, and discovery dates — recorded differences, stated as filed. See this exact package’s record →

Appendix A records, for every filing, where the bytes came from and how to prove they haven't changed.

Chain-of-custody card for an SEC 8-K filing: source URL, fetch timestamp, storage key with body-present badge, SHA-256 of fetched bytes and extraction input, and per-exhibit hashes
One filing's custody card: the sec.gov source URL, fetch timestamp, immutable storage key with its archive-presence badge, SHA-256 of the bytes as fetched — and every SEC exhibit hashed individually. See this exact package’s record →

The document carries its own verification details in print, not just in PDF metadata.

Signature block printed in the document footer: signer common name, certificate fingerprint, generation timestamp, and methodology link
The signature block printed in every package: signer, certificate fingerprint, generation timestamp — so the file verifies independently of us.

Assembled, not asserted

The underlying filings remain public at their sources. The package adds assembly, cross-filing comparison, provenance hashes, and a digital signature — it does not alter the records.

Provenance to the byte

Hashes at fetch time and at extraction input, the extraction model and prompt version per filing, and a server-side audit row for every generated document.

Frozen when you buy

Your copy is stored under a content-addressed key at first download and served unchanged for the life of the link.

The small print, up front

The signature is PAdES-B with byte-range tamper detection, made with our own published signing certificate — the fingerprint is printed in the document footer. A PDF reader that trusts only certificate-authority-issued signers will list the signer as unknown; the check that matters is that the fingerprint matches the published one and the byte range is intact.

The package is described by what it contains. It reports filed facts with their provenance; it draws no legal characterization of any company. Where a source document was never archived, the custody appendix says so on that row rather than implying otherwise.

How the signing and custody work.