HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
BANNER HEALTH
bd_ac773cf578b8482a · schema v1 · pii pii-v1
Full breach record for BANNER HEALTH →Banner Health disclosed two cybersecurity incidents in California in 2016. The first involved unauthorized access to patient servers from June 17 to July 7, 2016, exposing PHI, SSNs, and demographics. The second involved unauthorized access to payment card systems at food and beverage outlets from June 23 to July 7, 2016, exposing payment card data. Banner Health engaged forensic investigators, law enforcement, and Kroll for credit monitoring services.
California clockDiscovered Jul 13, 2016 → Notified Aug 3, 201621d ✓ CA 60-day OK21 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_0588cdfba1eacf3dWashington State AGfiled 2016-08-03Candidate
- bd_47377d5f3cbb422eNew Hampshire State AGfiled 2016-08-03Verified
- bd_84becbd39b03c2c2Montana State AGfiled 2016-08-03Verified
- bd_cb3e26b4ba0ad5ccOregon State AGfiled 2016-08-03Verified
Show 1 more filing ↓Show fewer ↑
- bd_efb36ded28ef2d7dHHS OCRfiled 2016-08-03Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-63197
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 3, 2016
- Raw hash
- d1e03ec4a5b55300c1982f4eecb53a0e6e63eb805e64f097089e7b67f9e00fe3
Reporting entity
- Name
- BANNER HEALTHnorm: banner health
- Domain
- bannerhealth.com
Victim entity
- Name
- BANNER HEALTHnorm: banner health
- Domain
- bannerhealth.com
Incident
- Discovered
- Jul 13, 2016
- Materiality determined
- —
- Notification sent
- Aug 3, 2016
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- contacted law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 21 days(21 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 21d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 13, 2016→ Notified: Aug 3, 201621d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.