Comprehensive Health Services
bd_9e4f9cb525e6052d · schema v1 · pii pii-v1
Full breach record for Comprehensive Health Services →Comprehensive Health Services (CHS) disclosed a cyber intrusion affecting invoicing files pre-dating 2019. The breach occurred between April 9, 2020, and October 22, 2020, with unauthorized access discovered on November 3, 2021. The incident involved the unauthorized acquisition of personal information, including names and contact details, of current and former employees of client agencies. CHS engaged cybersecurity experts and reported the incident to the FBI. Remediation included deploying endpoint detection and response tools, replacing threat monitoring vendors, and offering 24 months of complimentary credit monitoring and identity protection through Equifax to affected individuals.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-551741
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 16, 2022
- Raw hash
- c5f4adf9555cec6f6aee5e267e3ac6e11c1a287c86657dc57578fea245326f7f
Reporting entity
- Name
- Comprehensive Health Servicesnorm: comprehensive health
- Industry
- healthcare
Victim entity
- Name
- Comprehensive Health Servicesnorm: comprehensive health
- Industry
- healthcare
Incident
- Discovered
- Nov 3, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Reported the incident to law enforcement, including the Federal Bureau of Investigation (FBI)
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 19 weeks(133 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.