Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumResolved
Healthcare Resource Group, Inc.
bd_6e682289739dc75d · schema v1 · pii pii-v1
Full breach record for Healthcare Resource Group, Inc. →Healthcare Resource Group, Inc. (HRG) notified individuals of a data breach involving unauthorized access to an employee's email account between November 4 and November 30, 2019. The incident was discovered on December 31, 2019, during an unrelated investigation. The compromised account contained personal information of HRG's clients, specifically patients of Barlow Respiratory Hospital. HRG engaged forensic investigators, secured the account, notified law enforcement, and provided 12 months of identity monitoring services to affected individuals.
California clockDiscovered Dec 31, 2019 → Notified Mar 11, 202071d ✗ CA 60-day late14 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-188964
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 7, 2020
- Raw hash
- ba74f7df07ef823c08119b792fc7114d8ebba48eeb87e91cc27d352404b374dc
Reporting entity
- Name
- Healthcare Resource Group, Inc.norm: healthcare resource
Victim entity
- Name
- Healthcare Resource Group, Inc.norm: healthcare resource
Incident
- Discovered
- Dec 31, 2019
- Materiality determined
- —
- Notification sent
- Mar 11, 2020
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- phishing_link
Compliance
- Time to disclose
- 14 weeks(98 days from discovery to filing)
- Compliance flags
- CA 60-day late · 71d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 31, 2019→ Notified: Mar 11, 202071d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.