MalwareRansomwareData EncryptedCustomer Data InvolvedEmployee Data InvolvedPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMINORMediumContained
NORTON HEALTHCARE, INC.
bd_434c49c9d0403911 · schema v1 · pii pii-v1
Full breach record for NORTON HEALTHCARE, INC. →Norton Healthcare, Inc. experienced a ransomware attack discovered on May 9, 2023. Unauthorized access to network storage devices occurred between May 7 and May 9, 2023. Affected data included PHI, PII (SSN, DOB, contact info), financial account numbers, and government IDs for patients, employees, and dependents. Norton Healthcare notified federal law enforcement, engaged forensic experts, terminated access, and offered two years of identity monitoring via Kroll.
Leak gap clock✗ Leak >180d30 weeks discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_0881b4fc047b0f64Maine State AGfiled 2023-12-08Candidate
- bd_426bccd437fdbc35Montana State AGfiled 2023-12-08Verified
- bd_64845bb10ad9fa4eWashington State AGfiled 2023-12-08Verified
- bd_6bc5c9b6118928e9South Carolina State AGfiled 2023-12-08Verified
Show 3 more filings ↓Show fewer ↑up to 5d gap
- bd_ec812b620ee89de8Vermont State AGfiled 2023-12-08Verified
- bd_8ea130c0a2330094New Hampshire State AGfiled 2023-12-11(3d gap)Verified
- bd_7bb3ea95da317ae3Oregon State AGfiled 2023-12-13(5d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-577640
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 8, 2023
- Raw hash
- 36293e7ce1d4c0f5dfd68e4845a02d5e58405c45f743722e67643289d029b356
Reporting entity
- Name
- NORTON HEALTHCARE, INC.norm: norton healthcare
- Domain
- nortonhealthcare.com
Victim entity
- Name
- NORTON HEALTHCARE, INC.norm: norton healthcare
- Domain
- nortonhealthcare.com
Incident
- Discovered
- May 9, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMINOR
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcement
Compliance
- Time to disclose
- 30 weeks(213 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.