HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICLowContained
San Francisco Department of Public Health
bd_5d4e4a5c52a98a02 · schema v1 · pii pii-v1
Full breach record for San Francisco Department of Public Health →San Francisco Department of Public Health (SFDPH) notified patients of a data breach involving third-party vendor Nuance Communications. An unauthorized former Nuance employee accessed patient records between November 20 and December 9, 2017. The breach exposed PHI including names, dates of birth, and medical records, but excluded SSNs or financial data. Law enforcement delayed notification during a criminal investigation. Nuance took the system offline immediately upon discovery.
California clockDiscovered Dec 9, 2017 → Notified May 11, 2018153d ✗ CA 60-day late22 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_55d794beb502891bHHS OCRfiled 2018-06-25(45d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-136120
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 11, 2018
- Raw hash
- fe9776a8c077e19ecb1af3776083a6243e1b7431e9508a555871ae8008849647
Reporting entity
- Name
- San Francisco Department of Public Healthnorm: san francisco department of public health
Victim entity
- Name
- San Francisco Department of Public Healthnorm: san francisco department of public health
Incident
- Discovered
- Dec 9, 2017
- Materiality determined
- —
- Notification sent
- May 11, 2018
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- FBI and the U.S. Department of Justice conducted a criminal investigationNotification and disclosure about the data security incident was delayed at the request of law enforcement
- Third party
- via Nuance Communications, Inc.
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 22 weeks(153 days from discovery to filing)
- Compliance flags
- CA 60-day late · 153d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 9, 2017→ Notified: May 11, 2018153d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.