HackingHealthcareHealthcareSupply Chain (3P Vendor)Employee Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTEMPLOYMENTMediumContained
Community Memorial Health System
bd_5b3d82eb2f92ba2a · schema v1 · pii pii-v1
Full breach record for Community Memorial Health System →Community Memorial Health System (CMHS) notified employees of a data breach at third-party vendor PaperlessPay Corporation. DHS alerted PaperlessPay on February 19, 2020 that an unknown individual was selling access to their client database on the dark web. The unauthorized person accessed PaperlessPay's SQL server on February 18, 2020, where CMHS employee pay stub and tax form data was stored, including names, addresses, SSNs, pay/withholdings, and in some cases bank account numbers. CMHS offered one year of free Experian IdentityWorks to affected employees.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-189495
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 27, 2020
- Raw hash
- 417afb1e25bb836d5514f2c602ef97ef9502932c85b48b8ccf8dff91aec47a34
Reporting entity
- Name
- Community Memorial Health Systemnorm: community memorial health system
Victim entity
- Name
- Community Memorial Health Systemnorm: community memorial health system
- Industry
- Healthcarellm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Apr 27, 2020
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTEMPLOYMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Department of Homeland Security (DHS) notified PaperlessPay of possible breach and conducted joint investigation with FBIFederal Bureau of Investigation (FBI) conducted joint investigation with DHSNotified California Attorney General
- Third party
- via PaperlessPay Corporation
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.