Social EngineeringHealthcareHealthcarePhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryPIIPHIIDENTITY_BASICHEALTH_BASICIDENTITY_GOVERNMENTMediumContained
Community Memorial Health System
bd_5f791db51475fcd1 · schema v1 · pii pii-v1
Full breach record for Community Memorial Health System →On June 22, 2017, a Community Memorial Health System (CMHS) employee's email account was compromised via a phishing email. The employee detected anomalies on June 23, 2017, prompting a password reset and investigation. CMHS's forensic consultant found indicators suggesting no personal information was accessed, though certainty could not be confirmed. Affected data potentially included patient names, medical record/account numbers, dates of service, health information, and for some patients, SSNs. CMHS offered 24-month identity theft and credit monitoring via AllClear ID.
California clockDiscovered Jun 23, 2017 → Notified Sep 5, 201774d ✗ CA 60-day late11 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_0c534258effa1084HHS OCRfiled 2017-09-05Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-101618
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 5, 2017
- Raw hash
- 8af41b78a185dff17fa40842177dae2d59f81841a7a4ded47675a9e5e3781556
Reporting entity
- Name
- Community Memorial Health Systemnorm: community memorial health system
Victim entity
- Name
- Community Memorial Health Systemnorm: community memorial health system
- Industry
- Healthcarellm
Incident
- Discovered
- Jun 23, 2017
- Materiality determined
- —
- Notification sent
- Sep 5, 2017
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICHEALTH_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566 PhishingT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_attachment
Compliance
- Time to disclose
- 11 weeks(74 days from discovery to filing)
- Compliance flags
- CA 60-day late · 74d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 23, 2017→ Notified: Sep 5, 201774d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.