HackingSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedDelayed DiscoveryPHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
L.A. Care Health Plan
bd_6ade23838f76d529 · schema v1 · pii pii-v1
Full breach record for L.A. Care Health Plan →L.A. Care Health Plan notified members of a data breach involving former vendor Conduent Business Services LLC. An unauthorized third party accessed Conduent's network between October 21, 2024, and January 13, 2025, obtaining files containing member names, dates of birth, claim numbers, dates of service, treatment costs, admission/discharge dates, and health insurance member information. One notification variant also included Social Security Numbers. Conduent secured networks, engaged forensic experts, notified law enforcement, and is enhancing security measures.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-625951
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 2, 2026
- Raw hash
- f9e40c1dc4ac70b957cd7bf81c270d0cce22c0ce2ebca521e6737b6a50f32d75
Reporting entity
- Name
- L.A. Care Health Plannorm: la care health plan
- Domain
- lacare.org
Victim entity
- Name
- L.A. Care Health Plannorm: la care health plan
- Domain
- lacare.org
Incident
- Discovered
- Jan 13, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Conduent Business Services LLC
Compliance
- Time to disclose
- 18 months(535 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.