County of Los Angeles Department of Mental Health
bd_8cf4b12b3cb8239e · schema v1 · pii pii-v1
Full breach record for County of Los Angeles Department of Mental Health →On March 20, 2024, the Los Angeles County Department of Mental Health experienced a phishing incident where an employee scanned a QR code from a malicious attachment, granting an external actor access to their Microsoft Office 365 account. The incident potentially exposed personal information including names, dates of birth, SSNs, addresses, phone numbers, medical record numbers, health insurance info, and treatment information. The department disabled affected accounts, reset credentials, engaged forensic specialists, and notified law enforcement and Microsoft. No evidence of data misuse was found.
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_d9847fc4e0964718HHS OCRfiled 2024-05-20(3d gap)Verified
- bd_0450a32caae6280cCalifornia State AGfiled 2024-03-22(56d gap)Verified
- bd_5770a98a6f25f686HHS OCRfiled 2024-03-22(56d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-585564
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 17, 2024
- Raw hash
- 25609c0d59110903873cbb6f177d8f8b28614bdbf3eac0a822e3a7b7572eaa0c
Reporting entity
- Name
- County of Los Angeles Department of Mental Healthnorm: county of los angeles department of mental health
Victim entity
- Name
- County of Los Angeles Department of Mental Healthnorm: county of los angeles department of mental health
Incident
- Discovered
- Mar 20, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.001 Spearphishing AttachmentT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_attachment
Compliance
- Time to disclose
- 8 weeks(58 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.