MalwareRansomwareSupply Chain (3P Vendor)Ransom DemandedRansom PaidData EncryptedData ExfiltratedIDENTITY_BASICHEALTH_BASICLowContained
Methodist Hospital of Southern California
bd_597393eee158ef0e · schema v1 · pii pii-v1
Full breach record for Methodist Hospital of Southern California →Methodist Hospital of Southern California notified patients of a ransomware attack on its third-party vendor, Blackbaud Inc., affecting the hospital's donor database. The attack occurred between Feb-May 2020. Patient data including names, contact info, DOB, and medical record numbers were copied. Blackbaud paid the ransom and confirmed data destruction. MHSC reported the incident to the CA Dept of Public Health.
California clockDiscovered Sep 9, 2020 → Notified Oct 20, 202041d ✓ CA 60-day OK8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_b797ec81be26bb95HHS OCRfiled 2020-11-04Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-195825
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 4, 2020
- Raw hash
- f48496337d0965a46257a5f0e9bf055581bf4174d949b92b9a9f81c0c354b00c
Reporting entity
- Name
- Methodist Hospital of Southern Californianorm: methodist hospital of southern california
Victim entity
- Name
- Methodist Hospital of Southern Californianorm: methodist hospital of southern california
Incident
- Discovered
- Sep 9, 2020
- Materiality determined
- —
- Notification sent
- Oct 20, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid AccountsT1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported this incident to the California Department of Public Health
- Third party
- via Blackbaud Inc.
- Initial access
- supply_chain
Compliance
- Time to disclose
- 8 weeks(56 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 41d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 9, 2020→ Notified: Oct 20, 202041d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.