HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPHIHEALTH_BASICIDENTITY_BASICLowContained
Central California Alliance for Health
bd_a2a618eeefb132f5 · schema v1 · pii pii-v1
Full breach record for Central California Alliance for Health →Central California Alliance for Health reported that on May 7, 2020, an unknown person illegally accessed employee email accounts for approximately one hour. Limited member health information, including care management records, claims info, dates of birth, demographic data, Medi-Cal IDs, and medical/referral information, may have been accessed. The organization shut down affected accounts, reset passwords, and mandated security training. No financial information or SSNs were involved.
California clockDiscovered May 7, 2020 → Notified Jun 26, 202050d ✓ CA 60-day OK8 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_73c9eb419d3e3e2bHHS OCRfiled 2020-07-02Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-191678
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 2, 2020
- Raw hash
- 92f623d18ff49740f83173977fd7ab7a4d719edbe56190c2259010f4a56f9c94
Reporting entity
- Name
- Central California Alliance for Healthnorm: central california alliance for health
- Domain
- ccah-alliance.org
Victim entity
- Name
- Central California Alliance for Healthnorm: central california alliance for health
- Domain
- ccah-alliance.org
Incident
- Discovered
- May 7, 2020
- Materiality determined
- —
- Notification sent
- Jun 26, 2020
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(56 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 50d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 7, 2020→ Notified: Jun 26, 202050d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.