DisclosureLens
Social EngineeringHealthcareHealthcarePhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPHIIdentity (basic)Health (basic)LowContained

CITY OF HOPE

bd_35bf1c6f9843005a · schema v1 · pii pii-v1

Severity

Low

Discovered

May 31, 2017

Filed

Aug 3, 2017

To disclose

9 weeks

Affected

Not disclosed

Linked

2 filings

Confidence

64%
Full breach record for CITY OF HOPE4 incidents on file

City of Hope experienced a phishing incident between May 31 and June 2, 2017, resulting in unauthorized access to four staff members' email accounts. Protected health information (PHI) including names, medical record numbers, and clinical data may have been accessed. The organization secured the accounts, engaged forensic investigators, and notified law enforcement. No evidence of data exfiltration or misuse was found.

California clockDiscovered May 31, 2017Notified Jul 21, 201751d CA 60-day OK9 weeks discovery → filing

Incident timeline

discovery → filing · 9 weeks / 64 days

May 31, 2017

Begins

May 31, 2017

Discovered

Aug 3, 2017

Filed

vs. sector median

3 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings

View merged incident ↗
HHS OCRAug 3 · first
California State AGAug 3 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.