MCLAREN HEALTH CARE CORPORATION
bd_8d2f2b3098afeb79 · schema v1 · pii pii-v1
Full breach record for MCLAREN HEALTH CARE CORPORATION →McLaren Health Care experienced unauthorized access to its network between July 28, 2023, and August 23, 2023. The organization became aware of suspicious activity on August 22, 2023. The breach potentially impacted patient information including names, Social Security numbers, health insurance details, dates of birth, and medical records such as diagnoses and treatment information. McLaren engaged third-party forensic specialists, secured its network, and is implementing additional administrative and technical safeguards. Identity theft protection services are being offered to affected individuals.
Linked disclosures
Why this link?Ransomware claims (2)
- bd_6326acdfc9de458aLeak Sitealphvfiled 2023-10-04(35d gap)Verified by operator
- bd_c4b2c0198b70501eLeak Sitealphvfiled 2023-09-29(40d gap)Verified
Regulatory filings (4) · sorted by filing gap
- bd_bd9b0633195a292fMontana State AGfiled 2023-11-09Verified by operator
- bd_c24689bd6cff46e0Maine State AGfiled 2023-11-09Verified
- bd_e37f582cfe47b024Idaho State AGfiled 2023-11-09Verified by operator
- bd_18c5455f0815045bHHS OCRfiled 2023-10-20(20d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-576339
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 9, 2023
- Raw hash
- 1f94ef475769978b649c8a1d26df07867e42e71fb4ed3923016d8a9e16aefced
Reporting entity
- Name
- MCLAREN HEALTH CARE CORPORATIONnorm: mclaren health care
- Domain
- mclaren.org
Victim entity
- Name
- MCLAREN HEALTH CARE CORPORATIONnorm: mclaren health care
- Domain
- mclaren.org
Incident
- Discovered
- Aug 22, 2023
- Materiality determined
- —
- Notification sent
- Nov 9, 2023
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 11 weeks(79 days from discovery to filing)
- Compliance flags
- CA 60-day late · 79dLeak >30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 22, 2023→ Notified: Nov 9, 202379d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.