Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedMulti-Stage ChainIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMINORMediumContained
University of Minnesota Physicians
bd_9c24cd515acb8e73 · schema v1 · pii pii-v1
Full breach record for University of Minnesota Physicians →University of Minnesota Physicians reported a data security event where cyber attackers used phishing emails to fraudulently access two employee email accounts between January 30 and February 4, 2020. The incident potentially exposed patient and employee data including names, addresses, SSNs, medical records, and payment card numbers. UMPhysicians secured the accounts, engaged forensic investigators, and offered 12 months of identity monitoring.
California clockDiscovered Jan 31, 2020 → Notified Mar 30, 202059d ✓ CA 60-day OK43 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_fbc943933d7fe487Montana State AGfiled 2020-11-25Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-196513
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 25, 2020
- Raw hash
- 11fec9364d495c37e34fa643ae0d247f8fb861417aa3b22fb0d276277a997a0c
Reporting entity
- Name
- University of Minnesota Physiciansnorm: university of minnesota physicians
- Domain
- mphysicians.org
Victim entity
- Name
- University of Minnesota Physiciansnorm: university of minnesota physicians
- Domain
- mphysicians.org
Incident
- Discovered
- Jan 31, 2020
- Materiality determined
- Mar 30, 2020
- Notification sent
- Mar 30, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMINOR
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified state and federal regulators where required
- Initial access
- phishing_link
Compliance
- Time to disclose
- 43 weeks(299 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 59d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 31, 2020→ Notified: Mar 30, 202059d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.