HackingCustomer Data InvolvedEmployee Data InvolvedPHIIDENTITY_BASICHEALTH_BASICLowContained
COVENANT HEALTH
bd_9f5aba5bf6f7a978 · schema v1 · pii pii-v1
Full breach record for COVENANT HEALTH →Covenant Health, Inc. reported a data security incident where an unauthorized party gained access to its IT environment on May 18, 2025. The organization detected unusual activity on May 26, 2025, and contained the incident. Affected data includes patient names, addresses, dates of birth, medical record numbers, health insurance information, and treatment details. Third-party forensic specialists were engaged to investigate. No specific malware or threat actor was identified.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_e35a31c1ca87c68cMontana State AGfiled 2026-01-02Verified
- bd_0201f6c42742ffa2New Hampshire State AGfiled 2025-12-31(2d gap)Verified
- bd_072a28e8c90a0e6bMaine State AGfiled 2025-12-31(2d gap)Verified
- bd_ef41caaf4af9cbfeVermont State AGfiled 2025-12-31(2d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 3d gap
- bd_95ce0e0243eda112Texas State AGfiled 2026-01-05(3d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-616528
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 2, 2026
- Raw hash
- d6683f801ecd964ba83e7a93f2f2c6478feb9055b4b52ef4455352852f30d9c5
Reporting entity
- Name
- COVENANT HEALTHnorm: covenant health
Victim entity
- Name
- COVENANT HEALTHnorm: covenant health
Incident
- Discovered
- May 26, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notice was also provided to federal law enforcement and appropriate agencies
Compliance
- Time to disclose
- 32 weeks(221 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.