Northern California Medical Associates, Inc.
bd_599039c6dce5ad88 · schema v1 · pii pii-v1
Full breach record for Northern California Medical Associates, Inc. →Northern California Medical Associates, Inc. (NCMA) experienced a ransomware incident where unauthorized access began on February 19, 2021, and resulted in encryption of servers and workstations on March 3, 2021. NCMA detected unusual activity on March 3, 2021, and confirmed data exfiltration on March 29, 2021. Affected data includes PHI, PII (SSN, driver's license), financial account info, and medical records. NCMA shut down network portions, reset passwords, engaged forensics, restored data, and notified law enforcement.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 19, 2021
Begins
Mar 3, 2021
Discovered
May 3, 2021
Filed
vs. sector median
4 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.