HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
Tri-City Healthcare District
bd_14769f608cc69152 · schema v1 · pii pii-v1
Full breach record for Tri-City Healthcare District →Tri-City Healthcare District, a healthcare entity based in Oceanside, CA, reported an external system breach (hacking) occurring on November 9, 2023, discovered on March 7, 2024. The incident compromised the names and Social Security Numbers of 7,847 individuals, including 3 Maine residents. The District notified affected individuals in writing on April 4, 2024, and offered 12 months of identity protection services, including credit monitoring and insurance reimbursement.
Maine clockDiscovered Mar 7, 2024 → Filed with AG Apr 4, 202428d ✓ ME AG ≤30d28 days discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_334b0f94cc2937a3Vermont State AGfiled 2024-04-04Verified
- bd_7d1174f7723f487cNew Hampshire State AGfiled 2024-04-04Verified
- bd_7d4d250c4c2f3d53Montana State AGfiled 2024-04-04Candidate
- bd_a04472851663bc22Indiana State AGfiled 2024-04-04Verified
Show 1 more filing ↓Show fewer ↑
- bd_d4c8c74c6bcb6edfCalifornia State AGfiled 2024-04-04Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/be245762-c5e7-48d5-92c7-2c292e910909.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 4, 2024
- Raw hash
- e680883d5ad03ba910ec611dcd86d07cf729b69e5094c08eed2e6f778556dced
Reporting entity
- Name
- Tri-City Healthcare Districtnorm: tri city healthcare district
Victim entity
- Name
- Tri-City Healthcare Districtnorm: tri city healthcare district
Incident
- Discovered
- Mar 7, 2024
- Materiality determined
- —
- Notification sent
- Apr 4, 2024
- Affected individuals
- 7,847
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed data breach notice with Maine Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 28d
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Mar 7, 2024→ Filed with AG: Apr 4, 202428d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.