MalwareRansomwareData ExfiltratedCustomer Data InvolvedPHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICMediumContained
Regal Medical Group, Inc.
bd_ad32657f6f5260f1 · schema v1 · pii pii-v1
Full breach record for Regal Medical Group, Inc. →Regal Medical Group, Inc. experienced a ransomware cyberattack resulting in unauthorized access and exfiltration of patient data. The breach occurred on or about December 1-2, 2022, and was discovered on December 8, 2022. Affected data includes names, SSNs (for some), dates of birth, addresses, diagnoses, treatment records, lab results, prescription data, radiology reports, health plan member numbers, and phone numbers. Regal notified law enforcement, HHS, and the CA AG, and offered one year of credit monitoring.
California clockDiscovered Dec 8, 2022 → Notified Feb 1, 202355d ✓ CA 60-day OK8 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_eefe874c3a262cefVermont State AGfiled 2023-03-28(55d gap)Verified
- bd_05946e9b114e6529California State AGfiled 2023-03-29(56d gap)Verified
- bd_67b4b668d0969a22Oregon State AGfiled 2023-04-11(69d gap)Verified
- bd_9905fab7e14e2975Washington State AGfiled 2023-04-11(69d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-562555
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 1, 2023
- Raw hash
- 45c1a482d73e2105bc896ba71566c10b24e56b6977e3bf3548d9d35cc8f1dc04
Reporting entity
- Name
- Regal Medical Group, Inc.norm: regal medical
Victim entity
- Name
- Regal Medical Group, Inc.norm: regal medical
Incident
- Discovered
- Dec 8, 2022
- Materiality determined
- —
- Notification sent
- Feb 1, 2023
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the U.S. Department of Health and Human Services of this incidentNotified the California Attorney General and other applicable regulatory agencies
Compliance
- Time to disclose
- 8 weeks(55 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 55d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 8, 2022→ Notified: Feb 1, 202355d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.