DisclosureLens
HackingHealthcareHealthcareSupply Chain (3P Vendor)Customer Data InvolvedPHIHealth (basic)Identity (basic)LowContained

Health Net of California

bd_9e18ea5d93b3f563 · schema v1 · pii pii-v1

Severity

Low

Discovered

Jan 25, 2021

Filed

Mar 25, 2021

To disclose

8 weeks

Affected

Not disclosed

Linked

2 filings

Confidence

65%
Full breach record for Health Net of California

Health Net of California notified individuals that their personal information may have been accessed via a cyber attack on its vendor, Accellion. The compromise occurred between January 7 and January 25, 2021, and was discovered on January 25, 2021. Affected data may include names, addresses, dates of birth, insurance ID numbers, and health information. Health Net activated its incident response plan, ceased using Accellion's services, and offered one year of identity protection.

California clockDiscovered Jan 25, 2021Notified Mar 24, 202158d CA 60-day OK8 weeks discovery → filing

Incident timeline

undetected · 18 days
discovery → filing · 8 weeks / 59 days

Jan 7, 2021

Begins

Jan 25, 2021

Discovered

Mar 25, 2021

Filed

vs. sector median

3 wks faster

This filing is one of 2 about the same incident.View merged incident
Part of Accellion supply-chain incident (2021) — a supply-chain cascade affecting multiple organizations.View cascade →

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings

View merged incident ↗
HHS OCRMar 25 · first
California State AGMar 25 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.