Social EngineeringPhishingStolen CredentialsBusiness Associate (HIPAA)Customer Data InvolvedEmployee Data InvolvedPHIIDENTITY_BASICHEALTH_BASICLowContained
Nemadji Research Corporation
bd_7a5adbaa561a616f · schema v1 · pii pii-v1
Full breach record for Nemadji Research Corporation →Nemadji Research Corporation, a business associate for the County of Los Angeles providing patient eligibility and billing services, experienced a data breach on March 28, 2019. An employee fell victim to a phishing email, compromising one email account used for County Department of Health Services communications. Personal and health information (PHI) of patients may have been exposed. Nemadji notified the FBI, CA AG, and HHS OCR, and offered one year of identity monitoring via Kroll.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_88721c67d6a71606HHS OCRfiled 2019-07-08Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-148744
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 8, 2019
- Raw hash
- 1fe5c8373e904002f58906efc0d2a0dadca639f73f47a0ff26d314caf7d0aac9
Reporting entity
- Name
- Nemadji Research Corporationnorm: nemadji research
Victim entity
- Name
- Nemadji Research Corporationnorm: nemadji research
Incident
- Discovered
- Mar 28, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of InvestigationNotified the State Attorney General’s OfficeNotified the U.S. Department of Health & Human Services’ Office for Civil Rights
- Initial access
- phishing_link
Compliance
- Time to disclose
- 15 weeks(102 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.