NorthBay Healthcare Corporation
bd_84b37cb0f778512b · schema v1 · pii pii-v1
Full breach record for NorthBay Healthcare Corporation →NorthBay Healthcare Corporation disclosed that an unauthorized third party gained access to certain files on its computer systems between January 11, 2024, and April 1, 2024. The organization identified suspicious activity on February 23, 2024, and engaged a forensic security firm and law enforcement. Affected data may include names, dates of birth, Social Security numbers, passport numbers, financial account numbers, medical information, biometric information, health insurance information, driver's license numbers, usernames, passwords, and credit/debit card details. The company is offering one year of complimentary credit monitoring through Experian IdentityWorks.
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_3e24cc6d7f940850Oregon State AGfiled 2025-01-29Candidate
- bd_48556d100c6d2adcMaine State AGfiled 2025-01-29Verified
- bd_9e74ae9ee1e29801Vermont State AGfiled 2025-01-29Verified
- bd_e0f4c14e6c397f7bMontana State AGfiled 2025-01-29Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-598007
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 29, 2025
- Raw hash
- fac168d2a6e4dbd21b5826d641e95b47f98d1d394e46c028bf020ffb9e4f57e4
Reporting entity
- Name
- NorthBay Healthcare Corporationnorm: northbay healthcare
Victim entity
- Name
- NorthBay Healthcare Corporationnorm: northbay healthcare
Incident
- Discovered
- Feb 23, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSPHIHEALTH_BASICBIOMETRICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 49 weeks(341 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.