HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTCriticalContained
Sutter Medical Foundation
bd_6c2beb7b1da46705 · schema v1 · pii pii-v1
Full breach record for Sutter Medical Foundation →Sutter Medical Foundation experienced a cybersecurity incident on April 26, 2013, involving unauthorized access to its electronic health record system. The breach affected approximately 205,489 individuals, exposing government-issued IDs, financial account numbers, and personal information. The organization engaged forensic investigators, notified law enforcement, and provided credit monitoring services to affected parties.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_23baf3556b652333HHS OCRfiled 2015-09-11Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-57764
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 11, 2015
- Raw hash
- fa6aa6660c3a8de62aa9d1d4cee344cbd872b18e98766a633ed97f009a9699e3
Reporting entity
- Name
- Sutter Medical Foundationnorm: sutter medical
Victim entity
- Name
- Sutter Medical Foundationnorm: sutter medical
Incident
- Discovered
- Apr 26, 2013
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 205,489
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Regulator citations
- Notified California Department of Justice
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 29 months(868 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.