DisclosureLens
HackingHealthcareHealthcareStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedEmployee Data InvolvedPHIIdentity (basic)Government IDHealth (basic)MediumContained

Palomar Health

bd_8c64d267d7bf4a75 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Mar 13, 2023

Filed

Jun 21, 2023

To disclose

14 weeks

Affected

Not disclosed

Confidence

65%
Full breach record for Palomar Health4 incidents on file

Palomar Health notified patients of a data breach involving its vendor, PharMerica. An unknown third party accessed PharMerica's systems on March 12-13, 2023. Affected data included names, addresses, dates of birth, Social Security numbers, medications, and health insurance information for patients who received services at Palomar Continuing Care Center or The Villas at Poway between 2001 and 2020. Palomar Health learned of the incident on May 31, 2023, and conducted its own investigation. PharMerica is offering one year of credit and identity theft monitoring.

Incident timeline

undetected · 1 days
discovery → filing · 14 weeks / 100 days

Mar 12, 2023

Begins

Mar 13, 2023

Discovered

Jun 21, 2023

Filed

vs. sector median

+2 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.