HackingData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPHIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICBIOMETRICCREDENTIALSMediumContained
Palomar Health Medical Group
bd_618e29d3094b64b0 · schema v1 · pii pii-v1
Full breach record for Palomar Health Medical Group →Palomar Health Medical Group (PHMG) reported that an unauthorized actor gained access to certain files on its network from April 23, 2024, to May 5, 2024, and may have copied them. PHMG identified suspicious activity on May 5, 2024. The incident potentially impacted patient information including names, SSNs, health records, financial account info, and biometric data. PHMG notified law enforcement, enhanced security protocols, and offered credit monitoring. The notice was reissued in October 2025 to individuals who may not have previously received it.
California clockDiscovered May 5, 2024 → Notified Oct 15, 2025528d ✗ CA 60-day late18 months discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-612839
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 15, 2025
- Raw hash
- 197a75ffbb3e2157ccf737be0b7bc3c537393197582592da8ad60365e1a08d23
Reporting entity
- Name
- Palomar Health Medical Groupnorm: palomar health medical
- Domain
- palomarhealthmedicalgroup.org
Victim entity
- Name
- Palomar Health Medical Groupnorm: palomar health medical
- Domain
- palomarhealthmedicalgroup.org
Incident
- Discovered
- May 5, 2024
- Materiality determined
- —
- Notification sent
- Oct 15, 2025
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICBIOMETRICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified applicable state and federal regulators
Compliance
- Time to disclose
- 18 months(528 days from discovery to filing)
- Compliance flags
- CA 60-day late · 528d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 5, 2024→ Notified: Oct 15, 2025528d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.