HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIALMediumContained
Alameda Health System
bd_365de8008e69fa90 · schema v1 · pii pii-v1
Full breach record for Alameda Health System →Alameda Health System disclosed that an unauthorized external party remotely accessed an employee's email account on April 8, 2020. The incident was discovered on June 17, 2020. Affected data included names, dates of birth, medical record numbers, appointment dates, driver's license numbers, Social Security numbers, and health insurance information. The organization secured the account, engaged forensic investigators, and offered one year of identity protection services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-195465
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 22, 2020
- Raw hash
- ab91192b9c459bcca135c3f1732071bbb1090b6f95f74741f6f4b6a8f40aef3b
Reporting entity
- Name
- Alameda Health Systemnorm: alameda health system
- Domain
- alamedahealthsystem.org
Victim entity
- Name
- Alameda Health Systemnorm: alameda health system
- Domain
- alamedahealthsystem.org
Incident
- Discovered
- Jun 17, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 18 weeks(127 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.