CALIFORNIAHackingHealthcareHealthcareBusiness Associate (HIPAA)Supply Chain (3P Vendor)Customer Data InvolvedHEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNTMediumResolved
Axis Community Health
bd_6d1334c29fc9c50f · schema v1 · pii pii-v1
Full breach record for Axis Community Health →Axis Community Health (CA) reported to HHS on 2026-01-16 a Hacking/IT Incident affecting 3,579 individuals. A subcontractor of its business associate experienced a cyberattack that compromised PHI including financial and demographic information stored on a network server. The CE notified HHS, affected individuals, and the media, and provided complimentary credit monitoring services. Additional administrative, technical, and security safeguards were implemented by both the CE and BA.
HIPAA clock✓ HHS notified
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_ef58f141a6520d0dCalifornia State AGfiled 2026-01-16Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jan 16, 2026
- Raw hash
- 49db2d91ad512b29bc171a1d1e75dd7541803a8fd3deea04ef7671ba59ecc3f2
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Axis Community Healthnorm: axis community health
- Industry
- Health Care Services
Victim entity
- Name
- Axis Community Healthnorm: axis community health
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 3,579
- Data types
- HEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- Threat actor
- External
- Regulator citations
- HHS OCR notified
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.