Social EngineeringPhishingStolen CredentialsData ExfiltratedIDENTITY_BASICPHIHEALTH_BASICLowContained
Cancer Treatment Centers of America Midwestern Regional Medical Center
bd_444e33d05ef413eb · schema v1 · pii pii-v1
Full breach record for Cancer Treatment Centers of America Midwestern Regional Medical Center →Cancer Treatment Centers of America at Midwestern Regional Medical Center notified California AG of a security incident involving unauthorized access to an employee email account. The breach, occurring between Jan 12-18, 2021, exposed patient names, medical record numbers, health insurance info, and limited medical data. The company engaged forensic investigators and reset credentials.
California clockDiscovered Jan 18, 2021 → Notified Mar 19, 202160d ✓ CA 60-day OK9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_aaaaece068561403Oregon State AGfiled 2021-03-19Verified
- bd_b53d06d2c24e2011HHS OCRfiled 2021-03-19Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-539315
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 19, 2021
- Raw hash
- 7b5a9ae85535eb7f87665913b390779dd178cbd9e9938aa4d4a46da397d14ab2
Reporting entity
- Name
- Cancer Treatment Centers of America Midwestern Regional Medical Centernorm: cancer treatment centers of america midwestern regional medical center
Victim entity
- Name
- Cancer Treatment Centers of America Midwestern Regional Medical Centernorm: cancer treatment centers of america midwestern regional medical center
Incident
- Discovered
- Jan 18, 2021
- Materiality determined
- —
- Notification sent
- Mar 19, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPHIHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 60d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 18, 2021→ Notified: Mar 19, 202160d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.