DisclosureLens
MalwareHealthcareHealthcareRansomwareData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedIdentity (basic)PIILowContained

Valley Presbyterian Hospital

bd_b3a1e8ac88aee0f7 · schema v1 · pii pii-v1

Severity

Low

Discovered

Jul 31, 2020

Filed

Dec 30, 2020

To disclose

22 weeks

Affected

Not disclosed

Confidence

66%
Full breach record for Valley Presbyterian Hospital

Valley Presbyterian Hospital Foundation notified California residents of a data breach stemming from a ransomware attack on its third-party vendor, Blackbaud, Inc. The incident occurred between May 14 and May 20, 2020, involving encryption and exfiltration of data. Valley Presbyterian became aware of the incident on July 31, 2020. Affected data includes names and other personal information. The organization is providing 12 months of complimentary credit monitoring via TransUnion.

Incident timeline

undetected · 78 days
discovery → filing · 22 weeks / 152 days

May 14, 2020

Begins

Jul 31, 2020

Discovered

Dec 30, 2020

Filed

vs. sector median

+11 wks slower

Part of BLACKBAUD, INC. supply-chain incident (2020) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.