HackingData ExfiltratedCustomer Data InvolvedPHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICFINANCIAL_ACCOUNTCREDENTIALSMediumContained
Partnership HealthPlan of California
bd_139be031dd01e473 · schema v1 · pii pii-v1
Full breach record for Partnership HealthPlan of California →Partnership HealthPlan of California reported that on March 19, 2022, an unauthorized party accessed or took information from its network. Affected data may include names, SSNs, DOBs, driver's license numbers, medical record numbers, treatment, diagnosis, prescription info, health insurance info, member portal credentials, and addresses. The company engaged cybersecurity specialists, notified law enforcement, and is offering two years of credit monitoring.
California clockDiscovered Mar 19, 2022 → Notified May 18, 202260d ✓ CA 60-day OK9 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_13479c21b6c7bb13Washington State AGfiled 2022-05-18Candidate
- bd_33fa1e5cbdfe4d56Oregon State AGfiled 2022-05-18Verified
- bd_485a1f1fad2f5f50Montana State AGfiled 2022-05-18Verified
- bd_d7601862e566c677Maine State AGfiled 2022-05-18Verified
Show 1 more filing ↓Show fewer ↑
- bd_ee64421b22fda0a4HHS OCRfiled 2022-05-18Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-553531
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 18, 2022
- Raw hash
- 1f8e18fdfb37a98b7747c3dd35f6b1c25e378a0d2b6c4be7a248ba7f6966fcad
Reporting entity
- Name
- Partnership HealthPlan of Californianorm: partnership healthplan of california
- Domain
- partnershiphp.org
Victim entity
- Name
- Partnership HealthPlan of Californianorm: partnership healthplan of california
- Domain
- partnershiphp.org
Incident
- Discovered
- Mar 19, 2022
- Materiality determined
- —
- Notification sent
- May 18, 2022
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unknown
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified federal law enforcementNotifying regulatory authorities as required by law
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 60d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 19, 2022→ Notified: May 18, 202260d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.