Confirmed breach. Intrusion Jun 25, 2019–Jun 26, 2019, discovered Jun 26, 2019 — the first regulatory filing landed 44 days later. 12,805 individuals reported across the linked filings.
Discovery variance · Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster; needs two dated filings.
Regulatory clocksOregon✓ OR AG ≤45dHIPAA✓ HHS notifiedFull clock table in Litigation Timeline
HHS OCRState AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforced
Affected (total reported)
12,805
Data types
—
Jurisdictions
1
OR
Linked filings
2
HHS OCR · State AG
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
Breach window
Jun 25, 2019 → Jun 26, 2019
When the intrusion reportedly occurred, per the linked filings
Mid-Valley Behavioral Care Network reported a data breach to the Oregon Attorney General. The breach was reported on 2019-08-09. The breach occurred during 6/25/2019 - 6/26/2019. The breach was discovered on 6/26/2019. 12,805 individuals were affected. Notice was sent on 8/9/2019.
Affected (this filing): 12,805
OR AG ≤45d
🦫OREGONHHS OCRMost recentlinked via same-victim cross-source · 100%
Mid-Valley Behavioral Care Network reported to HHS on 2019-08-09 a Hacking/IT Incident affecting 10710 individuals. Breached information located on Email. The Business Associate was victim of a phishing scheme affecting ePHI (names, addresses, SSNs, clinical info) of Willamette Valley Community Health patients. Response included notifying HHS, CE, individuals, media, implementing safeguards, and staff retraining.
Affected (this filing): 10,710
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.