HackingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Monongalia Health System, Inc.
bd_540a4ff0c1f636b2 · schema v1 · pii pii-v1
Full breach record for Monongalia Health System, Inc. →Monongalia Health System, Inc. disclosed a cybersecurity incident occurring between Dec 8-19, 2021, involving unauthorized access to IT systems. The breach potentially exposed patient, provider, and employee data, including names, SSNs, medical records, and financial account numbers. Mon Health took systems offline, reset passwords, engaged forensic investigators, and notified law enforcement. Affected individuals were offered one year of Experian IdentityWorks.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-551316
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 28, 2022
- Raw hash
- 6f14923aa08d6ce30bebdea845a4fef898b31456f3589404cb11cbb260cb8ae0
Reporting entity
- Name
- Monongalia Health System, Inc.norm: monongalia health system
Victim entity
- Name
- Monongalia Health System, Inc.norm: monongalia health system
Incident
- Discovered
- Dec 18, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 weeks(72 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.