
On August 6, 2026 at 14:54 UTC, the extortion group Insomnia listed Park Place Behavioral Health Care — Osceola County's community behavioral health provider, in Kissimmee — on its leak site. The listing carries an estimated intrusion date of July 23. A plaintiffs' firm opened an investigation the following day, August 7.
As of August 14, Park Place has published no breach notice. The only documents on its website are its standard Notice of Privacy Practices in English and Spanish, which are boilerplate and describe no incident.
Nothing in that sequence is a compliance failure. That is the part worth sitting with.
Two clocks, running at different speeds
HIPAA gives a covered entity 60 days from the determination that protected health information was involved — and determination is not the same as discovery, which is where most of the elapsed time in these cases actually goes. On an estimated July 23 intrusion, the outer limit falls in late September. Park Place is comfortably inside it.
The regulator's channel is slower still. I pulled the HHS OCR breach portal on August 14: its most recent submission is dated July 24, three weeks back. Whatever an organization files this week does not become public there for weeks after. The portal is a record, not a notification system, and it was never built to be one.
Against that, the attacker's channel is instant. Insomnia posted, aggregators indexed it within the hour, and a law firm had it the next morning. There is no review step, no determination requirement, and no waiting period — publication is the extortion, so the timing is whatever hurts most.
So the org's disclosure plan, the regulator's portal and the attacker's leak site are three publication channels operating on 60 days, three weeks, and zero. Only one of them is under your control, and it is the slowest of the three.

As of August 14, the initial access vector has not been disclosed by anyone, and nothing in the public record establishes how the intrusion started. What follows is about the disclosure pattern, not this incident's technical cause.
The practice: know when your name appears, before someone calls you about it
The failure mode here is not being late. It is finding out secondhand — a reporter, a customer, a plaintiffs' firm — while your incident response is still working correctly and quietly through its first week. Three things prevent that, and none of them require a security team.
Monitor for your own name. Ransomware leak-site aggregators publish structured, queryable records; the Park Place entry above carries a group, an estimated attack date and an indexed timestamp, and it is free to read. Check your organization and your largest vendors on a schedule. This is a ten-minute weekly task or a scripted daily one, and its yield is almost always zero — which is exactly why it never gets assigned to anyone. Give it an owner and a checklist line, or it will not happen.
Draft the holding statement now. Not the notification letter, which is a legal document written once the facts are known — the two-paragraph statement you can publish within hours of learning your name is on a leak site, saying that you are aware, that you are investigating, and when you will next say something. Writing it under time pressure, with counsel in the room and a reporter waiting, is how organizations end up saying either nothing or too much. Written in advance, it needs a name and a date filled in.
Decide who speaks before you need to know. One named person, one named backup, and an agreed answer to "we cannot confirm that yet." The cost of this step is a meeting nobody wants to schedule, between legal, comms and whoever owns IT — which is why it is usually skipped and why it is the one that matters most at hour six.
If you do only one of the three, do the monitoring. A statement you have not written can be produced in an afternoon; the eight days you spent not knowing cannot be recovered.
What to check this week
- Search your organization's name, and your five largest vendors' names, on a ransomware leak-site aggregator. Most teams have never done this once.
- Do you have a holding statement drafted and approved, or only a notification template?
- Who publishes it, on what channel, and who approves it out of hours?
- If a reporter called your main line today about a breach you had not heard of, where would that call land?
- Does your incident plan have a step for "our name is already public," or does it assume you disclose first?
The pattern generalizes past healthcare. The same three-channel mismatch shows up wherever notification depends on completing an investigation first — and the investigation is usually a data inventory problem rather than a legal one. The extortion groups are not waiting for either.
North InfoSec runs AI-assisted penetration testing and security assessments, and advises on incident readiness of the kind described above. northinfosec.com