Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedPIIPHIHEALTH_BASICLowContained
Northwood
bd_7e7953fef7b021c8 · schema v1 · pii pii-v1
Full breach record for Northwood →Northwood, Inc., a durable medical equipment supplier, notified California residents of a data breach occurring between May 3 and May 6, 2019. An employee's email credentials were compromised via a phishing email, allowing unauthorized access to the account. The account contained healthcare provider exclusion status information (PHI). Northwood contained the breach, reset credentials, implemented MFA, and offered 2 years of credit monitoring via Kroll.
California clockDiscovered May 6, 2019 → Notified Jun 19, 201944d ✓ CA 60-day OK10 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_191444b326d59f10Montana State AGfiled 2019-07-15Verified
- bd_639c50815a8fcebfOregon State AGfiled 2019-07-15Verified
- bd_7f2db47cb52e499cHHS OCRfiled 2019-07-15Verified
- bd_1768919779e84892HHS OCRfiled 2019-07-16(1d gap)Candidate
Show 2 more filings ↓Show fewer ↑up to 3d gap
- bd_3a593e7557edc9f5HHS OCRfiled 2019-07-16(1d gap)Candidate
- bd_04b075f72f69eeccHHS OCRfiled 2019-07-12(3d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-148920
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 15, 2019
- Raw hash
- 7e36d34155ffac7e1b6216634ec7245891e367fd058b0168e5e115a4ee162082
Reporting entity
- Name
- Northwoodnorm: northwood
- Domain
- northwoodmfg.com
Victim entity
- Name
- Northwoodnorm: northwood
- Domain
- northwoodmfg.com
Incident
- Discovered
- May 6, 2019
- Materiality determined
- —
- Notification sent
- Jun 19, 2019
- Affected individuals
- Not disclosed
- Data types
- PIIPHIHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 10 weeks(70 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 44d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 6, 2019→ Notified: Jun 19, 201944d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.