DisclosureLens
HackingHealthcareProfessional ServicesHealthcareCustomer Data InvolvedDelayed DiscoveryIdentity (basic)Government IDFinancial accountHealth (basic)PHIMediumContained

Los Angeles Gay and Lesbian Community Services Center

bd_ae6e826d7413b311 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Nov 22, 2013

Filed

Dec 10, 2013

To disclose

18 days

Affected

Not disclosed

Linked

2 filings

Confidence

65%

The L.A. Gay & Lesbian Center experienced a criminal cyber attack between September 17, 2013, and November 8, 2013. The attack potentially exposed names, contact info, medical/healthcare info, dates of birth, credit card info, Social Security numbers, and health insurance account numbers. The intrusion was detected on November 22, 2013. The organization engaged forensic investigators, notified law enforcement, and offered one year of credit monitoring via Experian.

California clockDiscovered Nov 22, 2013Notified Dec 10, 201318d CA 60-day OK18 days discovery → filing

Incident timeline

undetected · 66 days
discovery → filing · 18 days

Sep 17, 2013

Begins

Nov 22, 2013

Discovered

Dec 10, 2013

Filed

vs. sector median

10 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings

View merged incident ↗
HHS OCRDec 10 · first
California State AGDec 10 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.