Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICPIIMediumActive
PRESBYTERIAN HEALTHCARE SERVICES
bd_2107a90b375cfa77 · schema v1 · pii pii-v1
Full breach record for PRESBYTERIAN HEALTHCARE SERVICES →Presbyterian Healthcare Services reported a phishing incident on May 9, 2019, discovered June 6, 2019. Unauthorized access was gained via deceptive emails to employee accounts containing patient PHI, names, SSNs, and DOBs. The organization secured accounts, notified law enforcement, and offered 12 months of credit monitoring and identity theft protection to affected individuals.
California clockDiscovered Jun 6, 2019 → Notified Aug 2, 201957d ✓ CA 60-day OK8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_444083c45b5375e4Montana State AGfiled 2019-08-02Verified
- bd_5284ecf8f1bd116eHHS OCRfiled 2019-08-02Verified
- bd_d61285150acc9ea9Oregon State AGfiled 2019-09-20(49d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-149440
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 2, 2019
- Raw hash
- 2b1f793913e13954b23c82d71c7e083a332ccb4bb2e004720c401557b1373d5d
Reporting entity
- Name
- PRESBYTERIAN HEALTHCARE SERVICESnorm: presbyterian healthcare
Victim entity
- Name
- PRESBYTERIAN HEALTHCARE SERVICESnorm: presbyterian healthcare
Incident
- Discovered
- Jun 6, 2019
- Materiality determined
- —
- Notification sent
- Aug 2, 2019
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICPII
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Alerted federal law enforcement
- Initial access
- phishing_link
Compliance
- Time to disclose
- 8 weeks(57 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 57d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 6, 2019→ Notified: Aug 2, 201957d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.