HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedIDENTITY_BASICHEALTH_BASICPIILowContained
Health Net of California
bd_9e18ea5d93b3f563 · schema v1 · pii pii-v1
Full breach record for Health Net of California →Health Net of California notified California AG regarding a breach involving its third-party vendor, Accellion. Between January 7 and January 25, 2021, an unknown malicious party accessed Accellion's file transfer platform, potentially exposing patient names, addresses, DOBs, insurance IDs, and health information. Health Net activated its incident response plan, ceased using Accellion, and provided one year of identity protection services to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-539506
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 25, 2021
- Raw hash
- 0eae91932105255635b0ac24bb9af8dc6493f968b15242a5b9a8f28bc8a89e43
Reporting entity
- Name
- Health Net of Californianorm: health net of california
Victim entity
- Name
- Health Net of Californianorm: health net of california
Incident
- Discovered
- Jan 25, 2021
- Materiality determined
- Mar 24, 2021
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASICPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Accellion is coordinating its incident response with law enforcement authorities, including the United States Federal Bureau of Investigation (FBI)
- Initial access
- supply_chain
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.