HackingData ExfiltratedCustomer Data InvolvedPHIIDENTITY_BASICHEALTH_BASICLowContained
CCM Health
bd_27ad049c600e5e1c · schema v1 · pii pii-v1
Full breach record for CCM Health →CCM Health notified California residents of a network security incident where unauthorized access occurred between April 3 and April 10, 2023. The attacker may have accessed and removed files containing personal information (name, date of birth) and protected health information (medical records, diagnoses, treatments). CCM Health contained the threat, engaged forensic investigators, and alerted law enforcement. No specific malware or threat actor was named.
California clockDiscovered Apr 3, 2023 → Notified Apr 3, 2024366d ✗ CA 60-day late12 months discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_f1a609c3ddaed8a3Maine State AGfiled 2024-03-13(23d gap)Verified by operator
- bd_1f76fbcbf7e394d9Washington State AGfiled 2024-03-12(24d gap)Candidate
- bd_9cd9daff80fca156California State AGfiled 2024-03-12(24d gap)Verified
- bd_c67b7a97167e034dHHS OCRfiled 2024-03-12(24d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 24d gap
- bd_f35303503d1c70e3Montana State AGfiled 2024-03-12(24d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-583580
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 5, 2024
- Raw hash
- d48d9592865b158e207103e8908afde16c1391b5d509519030b6f55bc4041c9c
Reporting entity
- Name
- CCM Healthnorm: ccm health
- Domain
- ccmhealthmn.com
Victim entity
- Name
- CCM Healthnorm: ccm health
- Domain
- ccmhealthmn.com
Incident
- Discovered
- Apr 3, 2023
- Materiality determined
- —
- Notification sent
- Apr 3, 2024
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Alerted law enforcement
Compliance
- Time to disclose
- 12 months(368 days from discovery to filing)
- Compliance flags
- CA 60-day late · 366d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 3, 2023→ Notified: Apr 3, 2024366d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.