HackingHealthcareHealthcareStolen CredentialsCapture App DataCustomer Data InvolvedDelayed DiscoveryPHIHEALTH_BASICIDENTITY_BASICLowContained
Central California Alliance for Health
bd_35da13dd9a5fceb0 · schema v1 · pii pii-v1
Full breach record for Central California Alliance for Health →Central California Alliance for Health notified members that on May 7, 2020, employee email accounts were accessed illegally by an unknown person for approximately one hour. The incident may have exposed member health information including care management records, claims information, dates of birth, demographic information, Medi-Cal ID numbers, medical information, and referral information. Financial information and SSNs were not included. A revised supplemental notice was issued in January 2021 after additional impacted individuals were identified.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-539067
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 11, 2021
- Raw hash
- b5e864a909c577ee334881ff976652f75548212a4832a394f7ef033d53c254f4
Reporting entity
- Name
- Central California Alliance for Healthnorm: central california alliance for health
- Domain
- ccah-alliance.org
Victim entity
- Name
- Central California Alliance for Healthnorm: central california alliance for health
- Domain
- ccah-alliance.org
- Industry
- Healthcarellm
Incident
- Discovered
- May 7, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 44 weeks(308 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.