HackingHealthcareHealthcareCapture App DataCustomer Data InvolvedDelayed DiscoveryPHIPIILowResolved
Summit Behavioral Healthcare, Inc.
bd_7c71a2b22d0e2df3 · schema v1 · pii pii-v1
Full breach record for Summit Behavioral Healthcare, Inc. →Summit Behavioral Healthcare (SBHC) experienced unauthorized access to two employee email accounts between approximately May 12–20, 2020. Suspicious activity was detected in late May 2020, but the investigation did not confirm that protected health information (PHI) was affected until January 21, 2021. A third-party forensics firm conducted the investigation. Affected individuals were notified in February 2021 and offered 12 months of free credit and identity monitoring through IDX.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_5b0678d99e52b7fdHHS OCRfiled 2021-02-26Verified
- bd_f5dc2a1e453a2a38Maine State AGfiled 2021-02-26Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-538369
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 26, 2021
- Raw hash
- 07fa31f0c5ef9a5f39ced65e3a08383caa5450665846071f6c1c38cf4ce03630
Reporting entity
- Name
- Summit Behavioral Healthcare, Inc.norm: summit behavioral healthcare
Victim entity
- Name
- Summit Behavioral Healthcare, Inc.norm: summit behavioral healthcare
- Industry
- Healthcarellm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.