Northern and Central California
bd_599039c6dce5ad88 · schema v1 · pii pii-v1
Full breach record for Northern and Central California →Northern California Medical Associates, Inc. (NCMA) reported a cybersecurity incident involving unauthorized access to its network beginning February 19, 2021, and culminating in the encryption of servers and workstations on March 3, 2021. The incident involved ransomware deployment and subsequent data exfiltration. Potentially affected data included patient names, contact information, Social Security numbers, driver's license numbers, financial account information, and medical/health insurance records. NCMA shut down network portions, reset passwords, engaged forensic specialists, restored data, and notified law enforcement.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-540500
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 3, 2021
- Raw hash
- a3ba2784991ad9f44d36c494fec2cca97d5d0719bf84b494e3f6d0ca1a791b56
Reporting entity
- Name
- Northern California Medical Associates, Inc.norm: northern california medical associates
Victim entity
- Name
- Northern and Central Californianorm: northern and central california
- Domain
- sutterhealth.org
Incident
- Discovered
- Mar 3, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHI
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- notifying regulators where necessary
Compliance
- Time to disclose
- 9 weeks(61 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.