CCM Health
bd_9cd9daff80fca156 · schema v1 · pii pii-v1
Full breach record for CCM Health →CCM Health notified the California Attorney General of a network security incident where an unauthorized party accessed its network between April 3 and April 10, 2023. The organization became aware of the potential unauthorized access on April 3, 2023. A forensic investigation concluded that files containing personal and health information, including Social Security Numbers, were accessed and removed. CCM Health contained the threat, engaged third-party cybersecurity professionals, and alerted law enforcement. Affected individuals are offered 12 months of complimentary credit monitoring.
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_1f76fbcbf7e394d9Washington State AGfiled 2024-03-12Candidate
- bd_c67b7a97167e034dHHS OCRfiled 2024-03-12Verified
- bd_f35303503d1c70e3Montana State AGfiled 2024-03-12Verified
- bd_f1a609c3ddaed8a3Maine State AGfiled 2024-03-13(1d gap)Verified by operator
Show 1 more filing ↓Show fewer ↑up to 24d gap
- bd_27ad049c600e5e1cCalifornia State AGfiled 2024-04-05(24d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-582358
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 12, 2024
- Raw hash
- 030fd2f24ace5fcb44a399eb7be30c6be9738e1533b74c45aaa05b9f357e20a8
Reporting entity
- Name
- CCM Healthnorm: ccm health
- Domain
- ccmhealthmn.com
Victim entity
- Name
- CCM Healthnorm: ccm health
- Domain
- ccmhealthmn.com
Incident
- Discovered
- Apr 3, 2023
- Materiality determined
- —
- Notification sent
- Mar 12, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 49 weeks(344 days from discovery to filing)
- Compliance flags
- CA 60-day late · 344d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 3, 2023→ Notified: Mar 12, 2024344d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.