CALIFORNIASocial EngineeringHealthcareHealthcarePhishingStolen CredentialsCustomer Data InvolvedHEALTH_BASICIDENTITY_BASICLowResolved
Community Memorial Health System
bd_0c534258effa1084 · schema v1 · pii pii-v1
Full breach record for Community Memorial Health System →On June 22, 2017, Community Memorial Health System (CA) experienced a phishing incident in which several hundred staff members received phishing emails. One employee working remotely followed the link, compromising her account credentials. The breach affected 959 individuals. Breached information was located in Email systems. The CE notified HHS, affected individuals, and media, disabled remote/mobile access, required credential resets, enforced two-factor authentication, and deployed centralized server log monitoring. OCR obtained corrective action assurances.
HIPAA clock✓ HHS notified11 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_5f791db51475fcd1California State AGfiled 2017-09-05Verified by operator
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Sep 5, 2017
- Raw hash
- cb475be2dcf829701d4c5b27eea1c770aaef9ffdf3992cb56d34fae75fc48928
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Community Memorial Health Systemnorm: community memorial health system
- Industry
- Health Care Services
Victim entity
- Name
- Community Memorial Health Systemnorm: community memorial health system
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Jun 22, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 959
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- OCR obtained assurances that the CE implemented corrective actions
- Initial access
- phishing_link
Compliance
- Time to disclose
- 11 weeks(75 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jun 22, 2017→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.