DisclosureLens
Social EngineeringHealthcareProfessional ServicesHealthcarePhishingStolen CredentialsBusiness Associate (HIPAA)Customer Data InvolvedEmployee Data InvolvedPHIIdentity (basic)Health (basic)LowContained

Nemadji Research Corporation

bd_7a5adbaa561a616f · schema v1 · pii pii-v1

Severity

Low

Discovered

Mar 28, 2019

Filed

Jul 8, 2019

To disclose

15 weeks

Affected

Not disclosed

Linked

2 filings

Confidence

66%
Full breach record for Nemadji Research Corporation

Nemadji Research Corporation, a business associate for the County of Los Angeles providing patient eligibility and billing services, experienced a data breach on March 28, 2019. An employee fell victim to a phishing email, compromising one email account used for County Department of Health Services communications. Personal and health information (PHI) of patients may have been exposed. Nemadji notified the FBI, CA AG, and HHS OCR, and offered one year of identity monitoring via Kroll.

Incident timeline

discovery → filing · 15 weeks / 102 days

Mar 28, 2019

Begins

Mar 28, 2019

Discovered

Jul 8, 2019

Filed

vs. sector median

+2 wks slower

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
HHS OCRJul 8 · first
California State AGJul 8 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.