Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIMediumContained
Albert Einstein Healthcare Network
bd_91059a29ec2ada09 · schema v1 · pii pii-v1
Full breach record for Albert Einstein Healthcare Network →Einstein Healthcare Network notified California regulators of a security incident involving unauthorized access to employee email accounts between August 5 and 17, 2020. The breach exposed patient information including names, DOBs, SSNs, and medical records. No evidence of actual misuse was found. The company engaged forensic investigators, secured accounts, and offered one year of credit monitoring to affected individuals.
California clockDiscovered Aug 10, 2020 → Notified Jan 21, 2021164d ✗ CA 60-day late24 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_b2710ea43f455881Washington State AGfiled 2021-01-25Verified
- bd_f3b57fa028fbc7e4Montana State AGfiled 2021-01-21(4d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-537414
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 25, 2021
- Raw hash
- 695fd0ecae42c49ca25d99b6e126876701a51aa7da314cad0a390db48ecf8cf5
Reporting entity
- Name
- Albert Einstein Healthcare Networknorm: albert einstein healthcare network
Victim entity
- Name
- Albert Einstein Healthcare Networknorm: albert einstein healthcare network
Incident
- Discovered
- Aug 10, 2020
- Materiality determined
- —
- Notification sent
- Jan 21, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 24 weeks(168 days from discovery to filing)
- Compliance flags
- CA 60-day late · 164d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 10, 2020→ Notified: Jan 21, 2021164d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.