HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICHEALTH_BASICLowContained
RADY CHILDREN'S HOSPITAL SAN DIEGO
bd_97f45a0d9ce3b6e0 · schema v1 · pii pii-v1
Full breach record for RADY CHILDREN'S HOSPITAL SAN DIEGO →Rady Children's Hospital San Diego disclosed a data security incident occurring between June 20, 2019, and January 3, 2020. Unauthorized access via an Internet port exposed patient names, gender, imaging study details, and in some cases, dates of birth and medical record numbers. No SSNs, credit card numbers, or radiology images were compromised. The hospital engaged forensic investigators, notified regulators, and offered 12 months of Experian identity protection services.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_50d81353ec6275baHHS OCRfiled 2020-02-21Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-187605
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 21, 2020
- Raw hash
- 64739a7a0e0fa0903faae40c16a593f1fe8a3d02afccefcf0c29704b2cf2fa49
Reporting entity
- Name
- RADY CHILDREN'S HOSPITAL SAN DIEGOnorm: rady children s hospital san diego
Victim entity
- Name
- RADY CHILDREN'S HOSPITAL SAN DIEGOnorm: rady children s hospital san diego
Incident
- Discovered
- Jan 3, 2020
- Materiality determined
- Feb 5, 2020
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.