County of Los Angeles
bd_22dc50bf9a61f922 · schema v1 · pii pii-v1
Full breach record for County of Los Angeles →5 incidents on fileOn May 13, 2016, the County of Los Angeles experienced a phishing email attack affecting approximately 108 employee email accounts. The attack potentially compromised personally identifiable information (PII) and protected health information (PHI) of service recipients, including names, SSNs, driver's license numbers, payment card info, bank account info, and medical records. The County notified law enforcement and relevant regulators (CDPH, CA AG, HHS OCR). Free identity monitoring was offered to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
May 13, 2016
Begins
May 13, 2016
Discovered
Dec 16, 2016
Filed
vs. sector median
+20 wks slower
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.