HackingVulnerability ExploitCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
SHARP HEALTHCARE
bd_b8b2f5541805219c · schema v1 · pii pii-v1
Full breach record for SHARP HEALTHCARE →On January 12, 2023, Sharp HealthCare identified suspicious activity on a server running its website. An unauthorized person gained access for a few hours and obtained a file containing patient names, internal identification/invoice numbers, payment amounts, and proof of payment to Sharp hospitals or medical groups. No SSNs, bank account details, credit card numbers, or clinical health information were involved. Sharp took servers offline, engaged a forensic firm, and enhanced website server security.
California clockDiscovered Jan 12, 2023 → Notified Feb 3, 202322d ✓ CA 60-day OK25 days discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_922e7378b9c64028HHS OCRfiled 2023-02-17(11d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-562755
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 6, 2023
- Raw hash
- acf00937695e159de678197081e72ba271ca1022bbac1e579bb3130609153462
Reporting entity
- Name
- SHARP HEALTHCAREnorm: sharp healthcare
- Domain
- sharp.com
Victim entity
- Name
- SHARP HEALTHCAREnorm: sharp healthcare
- Domain
- sharp.com
Incident
- Discovered
- Jan 12, 2023
- Materiality determined
- —
- Notification sent
- Feb 3, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 25 days(25 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 22d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 12, 2023→ Notified: Feb 3, 202322d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.