COMMUNITY RESEARCH FOUNDATION, INC.
bd_090a863c4f2966f2 · schema v1 · pii pii-v1
Full breach record for COMMUNITY RESEARCH FOUNDATION, INC. →Community Research Foundation (CRF) notified the California Attorney General of a data breach affecting protected health information (PHI). The incident occurred between October 6 and October 13, 2022, and was discovered on October 13, 2022. An unauthorized actor accessed files and data within CRF's systems. CRF engaged external cybersecurity experts, secured its environment, and offered 12 months of complimentary identity protection services via Experian to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 6, 2022
Begins
Oct 13, 2022
Discovered
Jun 29, 2023
Filed
vs. sector median
+25 wks slower
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitealphvbd_89acd6c85baa9ce62022-11-16 · +225dVerified by operator
Regulatory filings (3) · sorted by filing gap
- Indiana State AGbd_04ccb7b8d369e6282023-06-29Candidate
- Massachusetts State AGbd_4c6082bd699bd1122023-06-29Verified by operator
- HHS OCRbd_b03b7dc8312f0b352023-06-20 · +9dVerified
Filing propagation · 4 filings · 3 states
View merged incident ↗Pattern: first filing Jun 20 (CA), last Jun 29 (CA) — a 9-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.