Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryPHIHEALTH_BASICIDENTITY_BASICLowContained
Orange County Radiation Oncology Center
bd_040721a73900a648 · schema v1 · pii pii-v1
Full breach record for Orange County Radiation Oncology Center →Orange County Radiation Oncology Medical Group experienced an email phishing incident resulting in unauthorized access to patient information in a small number of email and SharePoint accounts between December 13, 2024, and December 16, 2024. The organization became aware of the incident on June 13, 2025. Affected data includes names and other patient health information. The organization is providing credit monitoring and additional cybersecurity training to staff.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-605500
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 15, 2025
- Raw hash
- 7ed3c8d048c8585bca2ce820563fcd0229d88d1ea44b25d60e417cc2c228dc7c
Reporting entity
- Name
- Orange County Radiation Oncology Centernorm: orange county radiation oncology center
- Domain
- ocroc.net
Victim entity
- Name
- Orange County Radiation Oncology Centernorm: orange county radiation oncology center
- Domain
- ocroc.net
Incident
- Discovered
- Jun 13, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 5 weeks(32 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.