Bryan County Ambulance Authority reported a data breach to the Montana Attorney General. The breach was reported on 2022-05-18. The breach occurred from 11/24/2021 to 11/29/2021. 1 Montana residents were affected.
Affected (this filing): 1
Clustered 2 filings across 2 jurisdictions · filed May 18, 2022. View entity profile → Other incidents for this victim →
incident inc_29cc1e5042c54cc9 · merge_method deterministic · confidence 100%
Time between earliest and latest filing
Not recorded for this incident
Discovery variance · Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster; needs two dated filings.
Health (basic) · Identity (basic)
MT OK
HHS OCR · State AG
Earliest sighting first · deep chronology in Litigation Timeline
Nov 24, 2021
When the intrusion reportedly occurred, per the linked filings
Bryan County Ambulance Authority reported a data breach to the Montana Attorney General. The breach was reported on 2022-05-18. The breach occurred from 11/24/2021 to 11/29/2021. 1 Montana residents were affected.
Affected (this filing): 1
Bryan County Ambulance Authority (BCAA), an Oklahoma emergency medical services provider, reported to HHS OCR on 2022-05-18 a Hacking/IT Incident (ransomware attack) affecting 14,273 individuals. Ransomware encrypted files on BCAA's network server containing patient ePHI. OCR found BCAA failed to conduct a compliant risk analysis. BCAA agreed to a $90,000 settlement and a 3-year corrective action plan — the first enforcement action under OCR's Risk Analysis Initiative. No business associate was involved.
Affected (this filing): 14,273
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.