CCM Health
bd_9cd9daff80fca156 · schema v1 · pii pii-v1
Full breach record for CCM Health →2 incidents on fileCCM Health notified the California Attorney General of a network security incident where an unauthorized party accessed its network between April 3 and April 10, 2023. The organization became aware of the potential unauthorized access on April 3, 2023. A forensic investigation concluded that files containing personal and health information, including Social Security Numbers, were accessed and removed. CCM Health contained the threat, engaged third-party cybersecurity professionals, and alerted law enforcement. Affected individuals are offered 12 months of complimentary credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 3, 2023
Begins
Apr 3, 2023
Discovered
Mar 12, 2024
Filed
vs. sector median
+37 wks slower
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- Washington State AGbd_1f76fbcbf7e394d92024-03-12Verified
- Indiana State AGbd_2fe1f2e2bb19b0b62024-03-12Verified
- HHS OCRbd_c67b7a97167e034d2024-03-12Verified
- Montana State AGbd_f35303503d1c70e32024-03-12Verified
Show 4 more filings ↓Show fewer ↑up to 24d gap
- Maine State AGbd_f1a609c3ddaed8a32024-03-13 · +1dVerified
- Massachusetts State AGbd_bd7b6becffb29f592024-03-15 · +3dVerified
- Illinois State AGbd_4b3bf823a2f121fa2024-03-01 · +11dCandidate
- California State AGbd_27ad049c600e5e1c2024-04-05 · +24dVerified
Filing propagation · 9 filings · 8 states
View merged incident ↗Pattern: first filing Mar 1 (IL), last Apr 5 (CA) — a 35-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.