Social EngineeringPhishingBECEmployee Data InvolvedTargetedIDENTITY_GOVERNMENTIDENTITY_BASICEMPLOYMENTHighContained
Saint Agnes Health Care, Inc.
bd_422360649d53ea71 · schema v1 · pii pii-v1
Full breach record for Saint Agnes Health Care, Inc. →Saint Agnes Medical Center experienced a Business Email Compromise (BEC) attack on May 2, 2016, where a scammer impersonated the CEO to request W-2 information via email. The incident compromised the 2015 W-2 data (including names, addresses, salaries, withholding info, and Social Security Numbers) of 2,812 employees. No patient data or systems were breached. The organization notified the California Attorney General and offered one year of Experian ProtectMyID Elite credit monitoring to affected employees.
California clockDiscovered May 2, 2016 → Notified May 4, 20162d ✓ CA 60-day OK3 days discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2,812 affectedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-61673
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 5, 2016
- Raw hash
- 28b1c267a48536ce4017e926ed36845e073393a71e6561b3e6bc65a5ca72702b
Reporting entity
- Name
- Saint Agnes Health Care, Inc.norm: saint agnes health care
Victim entity
- Name
- Saint Agnes Health Care, Inc.norm: saint agnes health care
Incident
- Discovered
- May 2, 2016
- Materiality determined
- —
- Notification sent
- May 4, 2016
- Affected individuals
- 2,812
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICEMPLOYMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Informing appropriate agencies, including the Office of the Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 3 days(3 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 2d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 2, 2016→ Notified: May 4, 20162d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.