HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPIIPHIIDENTITY_BASICHEALTH_BASICLowActive
Covenant Care California, LLC
bd_6dec4a99bf50f3f1 · schema v1 · pii pii-v1
Full breach record for Covenant Care California, LLC →Covenant Care California, LLC disclosed that an unauthorized actor gained access to certain employee email accounts associated with its Home Health services between February 24 and March 22, 2022. The company identified suspicious activity in February 2022. The incident potentially exposed patient and responsible party information, including names and health-related data. Covenant Care engaged forensic investigators, secured accounts, and is offering 12 months of identity monitoring via Kroll. The investigation is ongoing.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_444697bec78f4b28California State AGfiled 2022-05-09(44d gap)Verified
- bd_7661bb914420c3dbHHS OCRfiled 2022-05-06(47d gap)Verified
- bd_7b0ab00c082509beMontana State AGfiled 2022-05-06(47d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-554499
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 22, 2022
- Raw hash
- e6c19521fade6f41629cdd811dd68b39a2f893ede67f174809ca922ca6328fc9
Reporting entity
- Name
- Covenant Care California, LLCnorm: covenant care california
Victim entity
- Name
- Covenant Care California, LLCnorm: covenant care california
Incident
- Discovered
- Feb 1, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Reporting this incident to law enforcement and appropriate state and federal regulators
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 20 weeks(141 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.