Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICCREDENTIALSCriticalContained
PIH HEALTH, INC.
bd_a21953b1532e9ead · schema v1 · pii pii-v1
Full breach record for PIH HEALTH, INC. →PIH Health, a California healthcare provider, notified the California Attorney General of a data security incident involving unauthorized access to employee email accounts via a targeted phishing campaign. The breach affected approximately 159,879 California residents, exposing personal information, SSNs, driver's license numbers, medical information, and credentials. PIH Health engaged cybersecurity experts, reset passwords, and offered credit monitoring.
California clockDiscovered Jun 18, 2019 → Notified Jan 9, 2020205d ✗ CA 60-day late29 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed159,879 affectedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-185839
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 10, 2020
- Raw hash
- 53f8d653e57ee6bebe31b81ad0dc243eced744f12c7494378331ef12bd4d0b5e
Reporting entity
- Name
- Lewis Brisbois Bisgaard & Smith, PLLCnorm: lewis brisbois bisgaard smith
Victim entity
- Name
- PIH HEALTH, INC.norm: pih health
- Industry
- healthcare
Incident
- Discovered
- Jun 18, 2019
- Materiality determined
- Jan 10, 2020
- Notification sent
- Jan 9, 2020
- Affected individuals
- 159,879
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Notification of Data Security Incident sent to California Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 29 weeks(206 days from discovery to filing)
- Compliance flags
- CA 60-day late · 205d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 18, 2019→ Notified: Jan 9, 2020205d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.