DisclosureLens
HackingHealthcareHealthcareStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedPIIIdentity (basic)Financial accountLowContained

Rady Children’s Hospital – San Diego and Rady Children’s Hospital Foundation – San Diego

bd_218e4aca0eeeec55 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Oct 29, 2020

To disclose

Affected

Not disclosed

Confidence

65%

Rady Children’s Hospital – San Diego and its Foundation notified individuals that a third-party vendor, Blackbaud, experienced a data security incident. Between February 7, 2020, and June 4, 2020, an unauthorized party accessed backup files related to Blackbaud's fundraising and donor management software. On October 7, 2020, the hospital determined that some personal information was contained in these files. The incident involved potential exposure of personal data for community members who provided information to the hospital or foundation. The hospital retained cybersecurity experts, notified the FBI, and offered complimentary identity monitoring services through Experian. Blackbaud reported no evidence of misuse or public availability of the data.

Incident timeline

Feb 7, 2020

Begins

Oct 29, 2020

Filed

Part of BLACKBAUD, INC. supply-chain incident (2020) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.