Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTCriticalContained
Good Samaritan Hospital Retirement Income Plan
bd_09310420901426e0 · schema v1 · pii pii-v1
Full breach record for Good Samaritan Hospital Retirement Income Plan →Good Samaritan Hospital, Inc. disclosed a phishing incident affecting approximately 142,800 individuals, including 6 California residents. Unauthorized access to employee email accounts occurred between October 28 and November 8, 2019, potentially exposing PHI, SSNs, and financial data. The hospital engaged forensic investigators, reset credentials, and offered credit monitoring.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_ef28f42e16621531Montana State AGfiled 2020-07-01(28d gap)Candidate
- bd_3cd1a1e64491ca3bCalifornia State AGfiled 2020-05-29(61d gap)Verified
- bd_578004b36423aa6aHHS OCRfiled 2020-04-17(103d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-192546
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 29, 2020
- Raw hash
- 33ca2f11eade940e96211f3db1a413dfb8efb28798b07453ed69af4f9218e717
Reporting entity
- Name
- Good Samaritan Hospital Retirement Income Plannorm: good samaritan hospital retirement income plan
Victim entity
- Name
- Good Samaritan Hospital Retirement Income Plannorm: good samaritan hospital retirement income plan
Incident
- Discovered
- Nov 4, 2019
- Materiality determined
- Oct 22, 2019
- Notification sent
- —
- Affected individuals
- 142,800
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 38 weeks(268 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.