HackingData ExfiltratedCustomer Data InvolvedPHIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
Delta County Memorial Hospital District (Delta Health)
bd_1b8929159a2c6c15 · schema v1 · pii pii-v1
Full breach record for Delta County Memorial Hospital District (Delta Health) →Delta County Memorial Hospital District experienced unauthorized access to its network between May 27 and May 30, 2024. The attacker may have acquired files containing names, dates of birth, phone numbers, addresses, financial account information, medical information, health insurance information, Social Security numbers, and driver's license numbers. The organization notified law enforcement and engaged cybersecurity experts. Affected individuals are offered one year of Experian IdentityWorks credit monitoring.
California clockDiscovered May 30, 2024 → Notified Nov 1, 2024155d ✗ CA 60-day late35 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_21469493f21bc2afNew Hampshire State AGfiled 2025-01-31Verified
- bd_34943d644a6adeddMontana State AGfiled 2025-01-31Candidate
- bd_92d6656257b5349bOregon State AGfiled 2025-01-31Verified
- bd_bad5789d01d1b292Vermont State AGfiled 2025-01-31Verified
Show 1 more filing ↓Show fewer ↑
- bd_e7b66af0bbdf264eMaine State AGfiled 2025-01-31Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-598144
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 31, 2025
- Raw hash
- 423608d6535dded42c0e224310c1e21dd739210121007d1ea9eb86f33e2cdd78
Reporting entity
- Name
- Delta County Memorial Hospital District (Delta Health)norm: delta county memorial hospital district delta health
Victim entity
- Name
- Delta County Memorial Hospital District (Delta Health)norm: delta county memorial hospital district delta health
Incident
- Discovered
- May 30, 2024
- Materiality determined
- —
- Notification sent
- Nov 1, 2024
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 35 weeks(246 days from discovery to filing)
- Compliance flags
- CA 60-day late · 155d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 30, 2024→ Notified: Nov 1, 2024155d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.