Social EngineeringHealthcareTechnologyHealthcarePhishingStolen CredentialsMulti-Stage ChainCustomer Data InvolvedData ExfiltratedPHIHEALTH_BASICIDENTITY_BASICLowContained
Foundation Medicine, Inc.
bd_538872eb895c4bc8 · schema v1 · pii pii-v1
Full breach record for Foundation Medicine, Inc. →Foundation Medicine, Inc. notified the California AG of an email account compromise. An employee fell victim to phishing, resulting in unauthorized access to their email account on December 17, 2019 and January 14, 2020. The affected mailbox contained patient PHI including full name, date of birth, age, test name, ordering physician, and an FMI-assigned ID number. Financial data and SSNs were not involved.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_4d029767783c6aecHHS OCRfiled 2020-03-13Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-188282
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 13, 2020
- Raw hash
- fbff097bb61579cce9584f9964a2ec503d170159ba3407462cea52195f19a62c
Reporting entity
- Name
- Foundation Medicine, Inc.norm: foundation medicine
- Domain
- foundationmedicine.com
Victim entity
- Name
- Foundation Medicine, Inc.norm: foundation medicine
- Domain
- foundationmedicine.com
- Industry
- HealthcarellmTechnologyllm
Incident
- Discovered
- Jan 14, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566 PhishingT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.