Public Health Institute
bd_53e56dd806e7e2bc · schema v1 · pii pii-v1
Full breach record for Public Health Institute →The Public Health Institute (PHI) disclosed that a database containing email addresses and passwords for the California Environmental Health Tracking Program (CEHTP) was accessible on the internet without encryption for approximately 30 days, starting July 4, 2016. PHI discovered the misconfiguration on August 4, 2016. The incident affected user accounts for the CEHTP Water Boundary Tool, the retired CEHTP Geocoding Tool, and a retired California Department of Public Health system. PHI removed the database, reset passwords, and implemented bcrypt encryption. No other personal information was exposed.
J jump to incidentP pin to compareR raw source
Incident timeline
Jul 4, 2016
Begins
Aug 4, 2016
Discovered
Oct 5, 2016
Filed
vs. sector median
2 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.