HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIEMPLOYMENTMINORMediumContained
Morris Hospital & Healthcare Centers
bd_16c69f0d514cbd18 · schema v1 · pii pii-v1
Full breach record for Morris Hospital & Healthcare Centers →Morris Hospital & Healthcare Centers discovered a security incident on April 4, 2023, involving unauthorized exports of data to an external cloud storage platform. The breach affected current and former employees, their dependents, and patients. Exposed data included names, addresses, SSNs, dates of birth, medical record numbers, and diagnostic codes. Morris Hospital contained the incident, reset credentials, removed malicious files, and offered identity monitoring services.
California clockDiscovered Apr 4, 2023 → Notified Aug 17, 2023135d ✗ CA 60-day late19 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_8b00c8d9a79b225dVermont State AGfiled 2023-08-17Verified
- bd_8e26a3940f345506Montana State AGfiled 2023-08-17Verified
- bd_947fe245f50af0a8HHS OCRfiled 2023-08-17Verified
- bd_c57ca867432e837aMaine State AGfiled 2023-08-17Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-571977
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 17, 2023
- Raw hash
- 3ef3f4285ffc24a2297ea863978d6e2c5815b0e84c05cc91a6d5097009b9c0c3
Reporting entity
- Name
- Morris Hospital & Healthcare Centersnorm: morris hospital healthcare centers
Victim entity
- Name
- Morris Hospital & Healthcare Centersnorm: morris hospital healthcare centers
Incident
- Discovered
- Apr 4, 2023
- Materiality determined
- —
- Notification sent
- Aug 17, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIEMPLOYMENTMINOR
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 ChannelT1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 19 weeks(135 days from discovery to filing)
- Compliance flags
- CA 60-day late · 135d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 4, 2023→ Notified: Aug 17, 2023135d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.