Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTHighContained
OVERLAKE MEDICAL CENTER & CLINICS
bd_275afc788816b9c6 · schema v1 · pii pii-v1
Full breach record for OVERLAKE MEDICAL CENTER & CLINICS →Overlake Medical Center & Clinics reported a phishing incident in California affecting 1,087 residents. Between Dec 6-9, 2019, attackers used deceptive emails to steal employee credentials, gaining access to email accounts containing patient demographic, health insurance, and clinical data. Overlake secured accounts, engaged forensic counsel, reset passwords, and implemented multi-factor authentication.
California clockDiscovered Dec 9, 2019 → Notified Feb 4, 202057d ✓ CA 60-day OK9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_21978de6822b001bMontana State AGfiled 2020-02-07Candidate
- bd_69c1780df1b14199Oregon State AGfiled 2020-02-07Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-187100
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 7, 2020
- Raw hash
- 80fcc836a4bc744e5b7d4f53c942eda508270ac1bb9542df255fddd803037c05
Reporting entity
- Name
- OVERLAKE MEDICAL CENTER & CLINICSnorm: overlake medical center clinics
Victim entity
- Name
- OVERLAKE MEDICAL CENTER & CLINICSnorm: overlake medical center clinics
Incident
- Discovered
- Dec 9, 2019
- Materiality determined
- Feb 4, 2020
- Notification sent
- Feb 4, 2020
- Affected individuals
- 1,087
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Submitted Breach Notification to California AG
- Initial access
- phishing_link
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 57d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 9, 2019→ Notified: Feb 4, 202057d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.