MalwareRansomwareData ExfiltratedCustomer Data InvolvedPHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICMediumContained
Regal Medical Group, Inc.
bd_05946e9b114e6529 · schema v1 · pii pii-v1
Full breach record for Regal Medical Group, Inc. →Regal Medical Group, Inc. experienced a ransomware cyberattack resulting in unauthorized access and exfiltration of patient data. The breach occurred on or about December 1-2, 2022, and was discovered on December 8, 2022. Affected data includes names, SSNs, dates of birth, addresses, diagnoses, treatments, lab results, and prescription data. The organization engaged third-party vendors, notified law enforcement and regulators (HHS, CA AG), and offered one year of credit monitoring.
California clockDiscovered Dec 8, 2022 → Notified Feb 1, 202355d ✓ CA 60-day OK16 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_eefe874c3a262cefVermont State AGfiled 2023-03-28(1d gap)Verified
- bd_67b4b668d0969a22Oregon State AGfiled 2023-04-11(13d gap)Verified
- bd_9905fab7e14e2975Washington State AGfiled 2023-04-11(13d gap)Verified
- bd_ad32657f6f5260f1California State AGfiled 2023-02-01(56d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-564890
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 29, 2023
- Raw hash
- b73684e3120b471fb8353c0562844f830732c209adb93fea52e68af2919d0a1f
Reporting entity
- Name
- Regal Medical Group, Inc.norm: regal medical
Victim entity
- Name
- Regal Medical Group, Inc.norm: regal medical
Incident
- Discovered
- Dec 8, 2022
- Materiality determined
- —
- Notification sent
- Feb 1, 2023
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the U.S. Department of Health and Human Services of this incidentNotified the California Attorney General and other applicable regulatory agencies
Compliance
- Time to disclose
- 16 weeks(111 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 55d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 8, 2022→ Notified: Feb 1, 202355d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.