HackingData ExfiltratedCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
Mattapan Community Health Center, Inc.
bd_8c1d56e7ec667a72 · schema v1 · pii pii-v1
Full breach record for Mattapan Community Health Center, Inc. →Community Health Center, Inc. disclosed a data breach where a skilled criminal hacker accessed and exfiltrated patient data, including PHI, SSNs, and health insurance info. The breach occurred on Oct 14, 2024, and was discovered on Jan 2, 2025. The attacker was contained within hours. No ransomware was used. Identity protection services were offered to affected individuals.
California clockDiscovered Jan 2, 2025 → Notified Jan 30, 202528d ✓ CA 60-day OK28 days discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_23e0cf60b7f0d63eNew Hampshire State AGfiled 2025-01-30Verified
- bd_5ff62bff4e9d2059HHS OCRfiled 2025-01-30Verified
- bd_c45394c325d6e42dMaryland State AGfiled 2025-01-30Verified
- bd_dc1672c896df3fb8Indiana State AGfiled 2025-01-30Verified
Show 2 more filings ↓Show fewer ↑up to 1d gap
- bd_e052c57184b93892Maine State AGfiled 2025-01-30Verified
- bd_2889d3f868c83b1cMontana State AGfiled 2025-01-31(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-598047
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 30, 2025
- Raw hash
- bf7bafe591c6da5355b05ba781dcc53d6d72b6f67d448d92d3729ca42b1b77cf
Reporting entity
- Name
- Mattapan Community Health Center, Inc.norm: mattapan community health center
Victim entity
- Name
- Mattapan Community Health Center, Inc.norm: mattapan community health center
Incident
- Discovered
- Jan 2, 2025
- Materiality determined
- —
- Notification sent
- Jan 30, 2025
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 28d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 2, 2025→ Notified: Jan 30, 202528d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.