MalwareHealthcareTechnologyHealthcareRansomwareCapture Stored DataRansom DemandedData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)Business Associate (HIPAA)IDENTITY_BASICPIILowContained
ALVARIA, INC.
bd_aefa377a9796e6a8 · schema v1 · pii pii-v1
Full breach record for ALVARIA, INC. →On March 9, 2023, Alvaria, Inc., a workforce management and call center technology company, suffered a ransomware attack on its customer environment. Data associated with Shasta Community Health Center customers was accessed and exfiltrated, potentially including names, phone numbers, addresses, and healthcare provider names. Alvaria secured its networks, restored systems via backups, engaged forensic experts, and notified the FBI. Affected individuals were offered 24 months of complimentary Experian identity monitoring.
Leak gap clock⏱ Leak >90d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 11 about the same incident.View merged incident
A leak claim by hive about this victim predates this filing by 155 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_0f1c1d4399267551HHS OCRfiled 2023-05-26Verified
- bd_2b6b416f814bf327HHS OCRfiled 2023-05-26Verified
- bd_35a0583bd128af1dHHS OCRfiled 2023-05-26Verified
- bd_829fa9177a1f7e4fHHS OCRfiled 2023-05-26Verified
Show 6 more filings ↓Show fewer ↑up to 3d gap
- bd_86fab8777f09847aHHS OCRfiled 2023-05-26Verified
- bd_91ad84e8924f7ed1HHS OCRfiled 2023-05-26Verified
- bd_9384d7d17885ad15HHS OCRfiled 2023-05-26Verified
- bd_ab2b25d3361ed4acHHS OCRfiled 2023-05-26Verified
- bd_d557ad3b003f6a7dHHS OCRfiled 2023-05-26Verified
- bd_a4e87f4bc8c1de69California State AGfiled 2023-05-23(3d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-567290
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 26, 2023
- Raw hash
- 54efe66920eb4c37db1bdf024a1107470627d0212965073f765133cab835ee84
Reporting entity
- Name
- Shasta Community Health Centernorm: shasta community health center
- Domain
- shastahealth.org
Victim entity
- Name
- ALVARIA, INC.norm: alvaria
- Domain
- alvaria.com
- Industry
- HealthcarellmTechnologyllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified California Attorney General
- Third party
- via Alvaria, Inc.
Compliance
- Compliance flags
- Leak >90d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.