DisclosureLens
Social EngineeringHealthcareHealthcarePhishingCustomer Data InvolvedPHIHealth (basic)Identity (basic)LowContained

Hospice by the Bay

bd_29461ab6fabb4127 · schema v1 · pii pii-v1

Severity

Low

Discovered

Mar 10, 2020

Filed

Mar 27, 2020

To disclose

17 days

Affected

Not disclosed

Confidence

64%
Full breach record for Hospice by the Bay

Hospice by the Bay notified the California Attorney General of a data breach occurring on March 10, 2020. An unauthorized individual sent a phishing email impersonating an employee to obtain an electronic report containing personal health information, including names, medical record numbers, insurer names, and service charges. Social Security numbers were not impacted. The organization strengthened employee training and internal policies in response.

California clockDiscovered Mar 10, 2020Notified Mar 27, 202017d CA 60-day OK17 days discovery → filing

Incident timeline

discovery → filing · 17 days

Mar 10, 2020

Begins

Mar 10, 2020

Discovered

Mar 27, 2020

Filed

vs. sector median

10 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.