Social EngineeringPhishingCustomer Data InvolvedData ExfiltratedPHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Humboldt Independent Practice Association
bd_30f1742d35ef4a97 · schema v1 · pii pii-v1
Full breach record for Humboldt Independent Practice Association →Humboldt Independent Practice Association experienced a phishing campaign resulting in unauthorized access to a single email account between June 26 and July 1, 2024. The actor acquired protected health information (PHI), including names and potentially Social Security numbers. The company notified HHS OCR and offered credit monitoring.
California clockDiscovered Jun 28, 2024 → Notified Mar 6, 2025251d ✗ CA 60-day late47 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-603120
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 23, 2025
- Raw hash
- d260a7f82cfc737d6bc4c8a7d59089df8f696829129bb7cea5f8deb815245621
Reporting entity
- Name
- Humboldt Independent Practice Associationnorm: humboldt independent practice
Victim entity
- Name
- Humboldt Independent Practice Associationnorm: humboldt independent practice
Incident
- Discovered
- Jun 28, 2024
- Materiality determined
- —
- Notification sent
- Mar 6, 2025
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1114 Email CollectionT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Reported the incident to the Department of Health and Human Services with the Office of Civil Rights
- Initial access
- phishing_link
Compliance
- Time to disclose
- 47 weeks(329 days from discovery to filing)
- Compliance flags
- CA 60-day late · 251d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 28, 2024→ Notified: Mar 6, 2025251d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.