Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIMediumContained
Saint Alphonsus Health System
bd_8ed3b86c841639cb · schema v1 · pii pii-v1
Full breach record for Saint Alphonsus Health System →Saint Alphonsus Health System reported a phishing incident affecting employee email accounts between January 4 and January 6, 2021. Unauthorized access may have exposed patient data including names, addresses, dates of birth, and medical records. The company secured the account, retrained staff, and engaged Kroll to provide one year of free identity monitoring services to affected individuals.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_59ef7b672a01c380HHS OCRfiled 2021-03-04Candidate
- bd_bd2986380c1ca329Oregon State AGfiled 2021-03-04Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-538900
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 4, 2021
- Raw hash
- d23aab464af892f4c8524d911de1f7fda0b5c00d421fc51ae4b98c0f90984326
Reporting entity
- Name
- Saint Alphonsus Health Systemnorm: saint alphonsus health system
Victim entity
- Name
- Saint Alphonsus Health Systemnorm: saint alphonsus health system
Incident
- Discovered
- Jan 6, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 8 weeks(57 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.