HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Citrus Health Network
bd_590dd94a4bb16082 · schema v1 · pii pii-v1
Full breach record for Citrus Health Network →Citrus Valley Health Partners notified individuals of a data breach involving third-party vendor Jobscience. An unauthorized third party gained access to Jobscience's server on or around May 8, 2018, and exfiltrated data including names, addresses, SSNs, DOBs, and driver's license numbers. Jobscience reconfigured servers and reset passwords. CVHP offered 12 months of credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-146046
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 5, 2019
- Raw hash
- 26df1ab253a74f5172c5627d6e033d13500f199dd973be7ab42abf94786c4fe2
Reporting entity
- Name
- Citrus Health Networknorm: citrus health network
- Domain
- citrushealth.org
Victim entity
- Name
- Citrus Health Networknorm: citrus health network
- Domain
- citrushealth.org
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1041 Exfiltration Over C2 ChannelT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Law enforcement is aware of the incident
- Third party
- via Jobscience
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.