
A 30-provider multi-specialty practice in Nashville, headquartered in the city's HCA-affiliated healthcare-services corridor.
A business email compromise hit a billing administrator. The attacker spoofed a vendor invoice request, redirected approximately $185,000, and used the same access to download patient billing records — names, dates of birth, account information — for roughly 5,400 Tennessee patients.
Cyber Extortion funded the BEC investigation and partial funds recovery. Data Breach Response covered notification, credit monitoring, and HIPAA coordination. The TIPA safe harbor under § 47-18-3208 became central to the AG response — the practice could demonstrate reasonable security under NIST CSF, which limited liability scope materially.
Funds were partially recovered. The AG closed with documented remediation. The class action settled within limits. This is the kind of BEC-to-PHI scenario we map against your wire authorization controls and safe-harbor posture before binding.













