HackingStolen CredentialsData ExfiltratedDelayed DiscoveryTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Community Health Systems Professional Services Corporation
bd_86b0ceb5fecbf701 · schema v1 · pii pii-v1
Full breach record for Community Health Systems Professional Services Corporation →Community Health Systems Professional Services Corporation (CHSPSC) reported a cyber attack occurring between April 10 and June 24, 2014. An Advanced Persistent Threat (APT) group from China bypassed security measures and exfiltrated patient data, including names, addresses, birthdates, and Social Security numbers. The incident was discovered in July 2014. CHSPSC engaged federal law enforcement and forensic experts, contained the breach, and offered one year of free identity theft protection to affected individuals.
California clockDiscovered Jul 1, 2014 → Notified Aug 25, 201455d ✓ CA 60-day OK7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_e336e3697f6fb673HHS OCRfiled 2014-08-20Verified
- bd_104240a425a7ef34HHS OCRfiled 2014-08-21(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-46296
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 20, 2014
- Raw hash
- c91e7cbe0d3be0ba41e16ee5a0dd18bd7452eaa78cc917778d37ffd7a1078d5a
Reporting entity
- Name
- Community Health Systems Professional Services Corporationnorm: community health systems professional
Victim entity
- Name
- Community Health Systems Professional Services Corporationnorm: community health systems professional
Incident
- Discovered
- Jul 1, 2014
- Materiality determined
- —
- Notification sent
- Aug 25, 2014
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid AccountsT1190 Exploit Public-Facing Application
- Threat actor
- ExternalEspionage
- Regulator citations
- worked closely with federal law enforcement authorities
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 weeks(50 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 55d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 1, 2014→ Notified: Aug 25, 201455d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.