HackingData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
California Physicians' Services
bd_306e4ea520f2a2e7 · schema v1 · pii pii-v1
Full breach record for California Physicians' Services →California Physicians' Service d/b/a Blue Shield of California disclosed a data breach involving third-party vendor Sharecare Health Data Services. Between May 21 and June 26, 2018, an unknown third party accessed Sharecare servers containing member data, including names, addresses, DOBs, and SSNs (for a subset). Blue Shield notified members on February 15, 2019, offering credit monitoring. The incident involved unauthorized access and data exfiltration to locations outside the US.
California clockDiscovered Jun 26, 2018 → Notified Feb 15, 2019234d ✗ CA 60-day late33 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_c50ebb7a0ccf4b70HHS OCRfiled 2019-02-15Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-144778
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 15, 2019
- Raw hash
- 52649b1e2c705a107c744ac92c1231b6100a0433d78259ba60f59aac6834d9b8
Reporting entity
- Name
- California Physicians' Servicesnorm: california physicians
- Domain
- blueshieldca.com
Victim entity
- Name
- California Physicians' Servicesnorm: california physicians
- Domain
- blueshieldca.com
Incident
- Discovered
- Jun 26, 2018
- Materiality determined
- —
- Notification sent
- Feb 15, 2019
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Filed breach notification with California Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 33 weeks(234 days from discovery to filing)
- Compliance flags
- CA 60-day late · 234d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 26, 2018→ Notified: Feb 15, 2019234d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.