Discovery variance · Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster; needs two dated filings.
Regulatory clocksWashington⏱ WA AG >30dHIPAA✓ HHS notifiedFull clock table in Litigation Timeline
HHS OCRState AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforced
Affected (total reported)
21,325
Data types
—
Jurisdictions
1
WA
Linked filings
2
HHS OCR · State AG
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
Breach discoveredAG web form
Dec 12, 2022
Reported by WASHINGTON AG filing
60 days
🌲WASHINGTONHHS OCRFirst filinglinked via same-victim cross-source · 100%
Evergreen Treatment Services reported to HHS on 2023-02-10 a Hacking/IT Incident affecting 21,325 individuals. Breached information located on Network Server. The incident involved ransomware compromising PHI including names, addresses, DOB, SSNs, diagnoses, and medications. The CE provided credit monitoring and identity theft protection.
Affected (this filing): 21,325
HHS notified
🌲Washington State AGMost recentlinked via same-victim cross-source · 100%
Evergreen Treatment Services, a non-profit/charity sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2022-12-12 and filed notice on 2023-02-13. 11,247 Washington residents were affected. 63 days elapsed between awareness and notification. 0 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 11,247
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.