HackingHealthcareHealthcareCapture Stored DataData ExfiltratedCustomer Data InvolvedDelayed DiscoveryMulti-Stage ChainPIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
INTEGRIS Health
bd_9429099b2e32de21 · schema v1 · pii pii-v1
Full breach record for INTEGRIS Health →INTEGRIS Health, operating on behalf of INTEGRIS Health Community Hospitals in Oklahoma, notified patients of unauthorized access to a file on or about November 28, 2023 by an unknown external party. Affected data included names, dates of birth, demographic and admission/discharge information, medical record numbers, and/or Social Security numbers. INTEGRIS Health engaged cybersecurity specialists, implemented security enhancements, and offered 24 months of complimentary identity protection through IDX.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_4af6528e31e289b5New Hampshire State AGfiled 2024-03-26Verified
- bd_1a72e8c92bd614e4New Hampshire State AGfiled 2024-03-01(25d gap)Verified
- bd_9a9540162c4dedc2California State AGfiled 2024-03-01(25d gap)Verified
- bd_a668f84aed93d709Montana State AGfiled 2024-03-01(25d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 49d gap
- bd_38004de1f0a69ec4California State AGfiled 2024-02-06(49d gap)Candidate
- bd_5e34203f2729ecedNew Hampshire State AGfiled 2024-02-06(49d gap)Verified
- bd_71dc05c2bcb11149Washington State AGfiled 2024-02-06(49d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-583081
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 26, 2024
- Raw hash
- 3b2d614bd69d28de3741ab0fdcda0e5edef9b80f75f2aa2747ebf8da66b477fd
Reporting entity
- Name
- INTEGRIS Healthnorm: integris health
- Domain
- integrisandme.com
Victim entity
- Name
- INTEGRIS Healthnorm: integris health
- Domain
- integrisandme.com
- Industry
- Healthcarellm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Mar 26, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1119 Automated CollectionT1074 Data Staged
- Threat actor
- External
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.