HackingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIMediumContained
CCA Health Plans of California, Inc. f/k/a Vitality Health Plan of California, Inc.
bd_5fc4b4c732d79485 · schema v1 · pii pii-v1
Full breach record for CCA Health Plans of California, Inc. f/k/a Vitality Health Plan of California, Inc. →CCA Health Plans of California, Inc. (d/b/a CCA Health California) notified the California Attorney General's Office of a cybersecurity incident occurring between May 4, 2022, and September 16, 2022. An unauthorized party accessed systems and removed files containing member information, including names, SSNs, DOBs, government IDs, and PHI. The company engaged law enforcement and forensic investigators, secured systems, and offered 12 months of Experian IdentityWorks.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_fa6cf0593f160ae7HHS OCRfiled 2022-11-15Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-559229
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 15, 2022
- Raw hash
- 19b2b8764d964820f84eb7b540e3208a543bb1dda1ce2e1a2a3bce3788db54a0
Reporting entity
- Name
- CCA Health Plans of California, Inc. f/k/a Vitality Health Plan of California, Inc.norm: cca health plans of california inc f k a vitality health plan of california
Victim entity
- Name
- CCA Health Plans of California, Inc. f/k/a Vitality Health Plan of California, Inc.norm: cca health plans of california inc f k a vitality health plan of california
Incident
- Discovered
- Sep 16, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.