HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICLowContained
Mono County
bd_abaff2ae87653c44 · schema v1 · pii pii-v1
Full breach record for Mono County →Mono County, California, experienced a data breach involving unauthorized public access to its online COVID-19 statistics database between April 9, 2020, and July 14, 2020. The incident exposed Protected Health Information (PHI), including names, dates of birth, gender, race, region, and clinical notes. The County secured the database and notified affected individuals on July 28, 2020.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-194510
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 25, 2020
- Raw hash
- 0dd4acab9b27050dc4503efb0a33144562495bb4d0264997b275c7ecd3c29da8
Reporting entity
- Name
- Mono Countynorm: mono county
Victim entity
- Name
- Mono Countynorm: mono county
Incident
- Discovered
- Jul 28, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.