MalwareRansomwareData ExfiltratedData EncryptedSupply Chain (3P Vendor)Customer Data InvolvedRansom DemandedIDENTITY_BASICHEALTH_BASICLowActive
INOVA HEALTH SYSTEM FOUNDATION
bd_4cea0b8a1367835a · schema v1 · pii pii-v1
Full breach record for INOVA HEALTH SYSTEM FOUNDATION →Inova Health System reported a data security incident involving third-party provider Blackbaud. A ransomware attack occurred between February 7, 2020, and May 20, 2020. The threat actor exfiltrated patient and donor information, including names, addresses, dates of birth, phone numbers, provider names, dates of service, and philanthropic giving history. Inova engaged cybersecurity professionals and set up a response line. Blackbaud paid the threat actor to destroy the data.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_cf1753ab447b5254HHS OCRfiled 2020-09-09(6d gap)Verified
- bd_e64407193b9828fbWashington State AGfiled 2020-09-09(6d gap)Verified
- bd_c39af1065b967091Oregon State AGfiled 2020-09-22(7d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-194048
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 15, 2020
- Raw hash
- caf57006c830c484ff75ce7da371f97775248d98f2e0eceb9580bb7d9434d58b
Reporting entity
- Name
- INOVA HEALTH SYSTEM FOUNDATIONnorm: inova health system
Victim entity
- Name
- INOVA HEALTH SYSTEM FOUNDATIONnorm: inova health system
Incident
- Discovered
- Jul 16, 2020
- Materiality determined
- Aug 10, 2020
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Third party
- via Blackbaud
- Initial access
- supply_chain
Compliance
- Time to disclose
- 9 weeks(61 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.