Social EngineeringPhishingTargetedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIALMediumContained
Verity Health System of California, Inc.
bd_15fab38565d0aa8f · schema v1 · pii pii-v1
Full breach record for Verity Health System of California, Inc. →Verity Health System experienced a phishing incident on April 27, 2016, where an employee was targeted by a scammer impersonating a Verity executive. The employee disclosed names, addresses, Social Security numbers, and W-2 earnings information for current and former employees. No patient information or systems were breached. Verity notified law enforcement, engaged outside experts, and provided two years of free identity protection services through Equifax to affected employees.
California clockDiscovered May 22, 2016 → Notified May 23, 20161d ✓ CA 60-day OK9 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-62088
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 31, 2016
- Raw hash
- cea25193ea465fc9c5d820d77e895a7848d250a70362ae96d989d26f17332889
Reporting entity
- Name
- Verity Health System of California, Inc.norm: verity health system of california
Victim entity
- Name
- Verity Health System of California, Inc.norm: verity health system of california
Incident
- Discovered
- May 22, 2016
- Materiality determined
- —
- Notification sent
- May 23, 2016
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified state and federal law enforcement
- Initial access
- phishing_link
Compliance
- Time to disclose
- 9 days(9 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 1d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 22, 2016→ Notified: May 23, 20161d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.